Requirement 12: Support information security with organisational policies and programs
Technical controls need governance: policy, risk management, awareness, vendor oversight, and incident response.
Sub-requirements
A comprehensive information security policy is maintained
4 defined requirementsEstablish, publish, review (at least annually) and disseminate the policy.
View defined requirements →Acceptable use policies are defined
1 defined requirementDefine acceptable use for end-user technologies.
View defined requirements →Risks to the CDE are formally managed
4 defined requirementsPerform targeted risk analyses where the standard allows flexibility.
View defined requirements →PCI DSS compliance is managed
3 defined requirementsAssign responsibility for the compliance program (and, for service providers, executive oversight).
View defined requirements →PCI DSS scope is documented and validated
4 defined requirementsDocument and confirm scope at least annually and on significant change.
View defined requirements →Security awareness education is ongoing
5 defined requirementsTrain personnel at hire and at least annually, covering current threats.
View defined requirements →Personnel are screened
1 defined requirementScreen staff before hire to reduce insider risk, within local law.
View defined requirements →Third-party service provider (TPSP) risk is managed
5 defined requirementsMaintain a TPSP list, define responsibilities, and monitor their compliance.
View defined requirements →TPSPs support their customers’ compliance
2 defined requirementsIf you are a TPSP, acknowledge responsibility and provide evidence to customers.
View defined requirements →Suspected and confirmed incidents are responded to
8 defined requirementsMaintain and test an incident response plan covering card-data incidents.
View defined requirements →Tips
- ›Keep a responsibility matrix that splits each requirement between you and each TPSP.
- ›Re-validate scope annually, scope creep is the most common audit surprise.
Evidence to keep
- ✓Policy set with review dates
- ✓Scope document
- ✓Training records
- ✓TPSP responsibility matrix
- ✓Incident response plan and test records
Example
An annually-reviewed policy set, a named compliance owner, documented scope, annual training, a TPSP register with responsibility matrix, and a tested incident response plan.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.