A compromise will not automatically require recertification. The general consensus is that if the organization meets the reporting and notification requirements outlined in the Incident Response domain and there is no negligence, the certification will hold.  The issues that will cause the loss of certification may be late reporting, poor execution of the system security plan, and the security controls.

171 Comply
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.