Maintain an information security policy

Requirement 12: Support information security with organisational policies and programs

Technical controls need governance: policy, risk management, awareness, vendor oversight, and incident response.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 12 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

12.1

A comprehensive information security policy is maintained

4 defined requirements

Establish, publish, review (at least annually) and disseminate the policy.

View defined requirements →
12.2

Acceptable use policies are defined

1 defined requirement

Define acceptable use for end-user technologies.

View defined requirements →
12.3

Risks to the CDE are formally managed

4 defined requirements

Perform targeted risk analyses where the standard allows flexibility.

View defined requirements →
12.4

PCI DSS compliance is managed

3 defined requirements

Assign responsibility for the compliance program (and, for service providers, executive oversight).

View defined requirements →
12.5

PCI DSS scope is documented and validated

4 defined requirements

Document and confirm scope at least annually and on significant change.

View defined requirements →
12.6

Security awareness education is ongoing

5 defined requirements

Train personnel at hire and at least annually, covering current threats.

View defined requirements →
12.7

Personnel are screened

1 defined requirement

Screen staff before hire to reduce insider risk, within local law.

View defined requirements →
12.8

Third-party service provider (TPSP) risk is managed

5 defined requirements

Maintain a TPSP list, define responsibilities, and monitor their compliance.

View defined requirements →
12.9

TPSPs support their customers’ compliance

2 defined requirements

If you are a TPSP, acknowledge responsibility and provide evidence to customers.

View defined requirements →
12.10

Suspected and confirmed incidents are responded to

8 defined requirements

Maintain and test an incident response plan covering card-data incidents.

View defined requirements →

Tips

  • Keep a responsibility matrix that splits each requirement between you and each TPSP.
  • Re-validate scope annually, scope creep is the most common audit surprise.

Evidence to keep

  • Policy set with review dates
  • Scope document
  • Training records
  • TPSP responsibility matrix
  • Incident response plan and test records

Example

An annually-reviewed policy set, a named compliance owner, documented scope, annual training, a TPSP register with responsibility matrix, and a tested incident response plan.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map