All PCI DSS v4.0.1 Controls
Every one of the 249 controls in PCI DSS v4.0.1, each with its requirement text, the testing procedures an assessor uses, and the evidence to prepare.
Every control in the standard, grouped by requirement. Each has its own page with the requirement in full, the testing procedures that define what evidence you need, and its related controls. 249 of the 249 also carry written implementation guidance.
Requirement 1: Install and Maintain Network Security Controls
Requirement overview · 19 controls
1.1
| Control | What it requires | Guidance |
|---|---|---|
| 1.1.1 | All security policies and operational procedures that are identified in Requirement 1… | Yes |
| 1.1.2 | Roles and responsibilities for performing activities in Requirement 1 are documented, assigned… | Yes |
1.2
| Control | What it requires | Guidance |
|---|---|---|
| 1.2.1 | Configuration standards for NSC rulesets… | Yes |
| 1.2.2 | All changes to network connections and to configurations of NSCs are approved and managed… | Yes |
| 1.2.3 | An accurate network diagram(s) is maintained that shows all connections between the CDE… | Yes |
| 1.2.4 | An accurate data-flow diagram(s) is maintained that meets… | Yes |
| 1.2.5 | All services, protocols, and ports allowed are identified, approved… | Yes |
| 1.2.6 | Security features are defined and implemented for all services, protocols… | Yes |
| 1.2.7 | Configurations of NSCs are reviewed at least once every six months to confirm they are relevant… | Yes |
| 1.2.8 | Configuration files for NSCs… | Yes |
1.3
| Control | What it requires | Guidance |
|---|---|---|
| 1.3.1 | Inbound traffic to the CDE is restricted… | Yes |
| 1.3.2 | Outbound traffic from the CDE is restricted… | Yes |
| 1.3.3 | NSCs are installed between all wireless networks and the CDE… | Yes |
1.4
| Control | What it requires | Guidance |
|---|---|---|
| 1.4.1 | NSCs are implemented between trusted and untrusted networks | Yes |
| 1.4.2 | Inbound traffic from untrusted networks to trusted networks is restricted… | Yes |
| 1.4.3 | Anti-spoofing measures are implemented to detect and block forged source IP addresses… | Yes |
| 1.4.4 | System components that store cardholder data are not directly accessible from untrusted networks | Yes |
| 1.4.5 | The disclosure of internal IP addresses and routing information is limited to only authorized… | Yes |
1.5
| Control | What it requires | Guidance |
|---|---|---|
| 1.5.1 | Security controls are implemented on any computing devices… | Yes |
Requirement 2: Apply Secure Configurations to All System Components
Requirement overview · 11 controls
2.1
| Control | What it requires | Guidance |
|---|---|---|
| 2.1.1 | All security policies and operational procedures that are identified in Requirement 2… | Yes |
| 2.1.2 | Roles and responsibilities for performing activities in Requirement 2 are documented, assigned… | Yes |
2.2
| Control | What it requires | Guidance |
|---|---|---|
| 2.2.1 | Configuration standards are developed, implemented, and maintained… | Yes |
| 2.2.2 | Vendor default accounts… | Yes |
| 2.2.3 | Primary functions requiring different security levels… | Yes |
| 2.2.4 | Only necessary services, protocols, daemons, and functions are enabled… | Yes |
| 2.2.5 | If any insecure services, protocols, or daemons are present… | Yes |
| 2.2.6 | System security parameters are configured to prevent misuse | Yes |
| 2.2.7 | All non-console administrative access is encrypted using strong cryptography | Yes |
2.3
| Control | What it requires | Guidance |
|---|---|---|
| 2.3.1 | For wireless environments connected to the CDE or transmitting account data, all wireless vendor defaults are changed at installation or are confirmed to be secure, including but not limited… | Yes |
| 2.3.2 | For wireless environments connected to the CDE or transmitting account data, wireless encryption keys are changed… | Yes |
Requirement 3: Protect Stored Account Data
Requirement overview · 29 controls
3.1
| Control | What it requires | Guidance |
|---|---|---|
| 3.1.1 | All security policies and operational procedures that are identified in Requirement 3… | Yes |
| 3.1.2 | Roles and responsibilities for performing activities in Requirement 3 are documented, assigned… | Yes |
3.2
| Control | What it requires | Guidance |
|---|---|---|
| 3.2.1 | Account data storage is kept to a minimum through implementation of data retention and disposal… | Yes |
3.3
| Control | What it requires | Guidance |
|---|---|---|
| 3.3.1 | SAD is not stored after authorization, even if encrypted | Yes |
| 3.3.1.1 | The full contents of any track are not stored upon completion of the authorization process | Yes |
| 3.3.1.2 | The card verification code is not stored upon completion of the authorization process | Yes |
| 3.3.1.3 | The personal identification number (PIN) and the PIN block are not stored upon completion… | Yes |
| 3.3.2 | SAD that is stored electronically prior to completion of authorization is encrypted using… | Yes |
| 3.3.3 | Issuers: Any storage of sensitive authentication data… | Yes |
3.4
| Control | What it requires | Guidance |
|---|---|---|
| 3.4.1 | PAN is masked when displayed… | Yes |
| 3.4.2 | When using remote-access technologies, technical controls prevent copy and/or relocation of PAN… | Yes |
3.5
| Control | What it requires | Guidance |
|---|---|---|
| 3.5.1 | PAN is rendered unreadable anywhere it is stored by using any of the following approaches… | Yes |
| 3.5.1.1 | Hashes used to render PAN unreadable (per the first bullet of Requirement 3.5.1) are keyed… | Yes |
| 3.5.1.2 | If disk-level or partition-level encryption… | Yes |
| 3.5.1.3 | If disk-level or partition-level encryption is used… | Yes |
3.6
| Control | What it requires | Guidance |
|---|---|---|
| 3.6.1 | Procedures are defined and implemented to protect cryptographic keys used to protect stored… | Yes |
| 3.6.1.1 | Service providers: A documented description of the cryptographic architecture is maintained… | Yes |
| 3.6.1.2 | Secret and private keys used to protect stored account data are stored in one (or more)… | Yes |
| 3.6.1.3 | Access to cleartext cryptographic key components is restricted to the fewest number… | Yes |
| 3.6.1.4 | Cryptographic keys are stored in the fewest possible locations | Yes |
3.7
| Control | What it requires | Guidance |
|---|---|---|
| 3.7.1 | Key-management policies and procedures are implemented to include generation of strong… | Yes |
| 3.7.2 | Key-management policies and procedures are implemented to include secure distribution… | Yes |
| 3.7.3 | Key-management policies and procedures are implemented to include secure storage… | Yes |
| 3.7.4 | Key management policies and procedures are implemented for cryptographic key changes for keys… | Yes |
| 3.7.5 | Key management policies procedures are implemented to include the retirement, replacement… | Yes |
| 3.7.6 | Where manual cleartext cryptographic key-management operations are performed by personnel… | Yes |
| 3.7.7 | Key management policies and procedures are implemented to include the prevention… | Yes |
| 3.7.8 | Key management policies and procedures are implemented to include that cryptographic key… | Yes |
| 3.7.9 | Service providers: Where a service provider shares cryptographic keys with its customers for transmission… | Yes |
Requirement 4: Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
Requirement overview · 6 controls
4.1
| Control | What it requires | Guidance |
|---|---|---|
| 4.1.1 | All security policies and operational procedures that are identified in Requirement 4… | Yes |
| 4.1.2 | Roles and responsibilities for performing activities in Requirement 4 are documented, assigned… | Yes |
4.2
| Control | What it requires | Guidance |
|---|---|---|
| 4.2.1 | Strong cryptography and security protocols… | Yes |
| 4.2.1.1 | An inventory of the entity’s trusted keys and certificates used to protect PAN during… | Yes |
| 4.2.1.2 | Wireless networks transmitting PAN or connected to the CDE use industry best practices… | Yes |
| 4.2.2 | PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies | Yes |
Requirement 5: Protect All Systems and Networks from Malicious Software
Requirement overview · 13 controls
5.1
| Control | What it requires | Guidance |
|---|---|---|
| 5.1.1 | All security policies and operational procedures that are identified in Requirement 5… | Yes |
| 5.1.2 | Roles and responsibilities for performing activities in Requirement 5 are documented, assigned… | Yes |
5.2
| Control | What it requires | Guidance |
|---|---|---|
| 5.2.1 | An anti-malware solution(s) is deployed on all system components… | Yes |
| 5.2.2 | The deployed anti-malware solution(s)… | Yes |
| 5.2.3 | Any system components that are not at risk for malware are evaluated periodically… | Yes |
| 5.2.3.1 | The frequency of periodic evaluations of system components identified as not at risk… | Yes |
5.3
| Control | What it requires | Guidance |
|---|---|---|
| 5.3.1 | The anti-malware solution(s) is kept current via automatic updates | Yes |
| 5.3.2 | The anti-malware solution(s)… | Yes |
| 5.3.2.1 | If periodic malware scans are performed to meet Requirement 5.3.2… | Yes |
| 5.3.3 | For removable electronic media, the anti-malware solution(s)… | Yes |
| 5.3.4 | Audit logs for the anti-malware solution(s) are enabled and retained in accordance… | Yes |
| 5.3.5 | Anti-malware mechanisms cannot be disabled or altered by users, unless specifically documented… | Yes |
5.4
| Control | What it requires | Guidance |
|---|---|---|
| 5.4.1 | Processes and automated mechanisms are in place to detect and protect personnel against… | Yes |
Requirement 6: Develop and Maintain Secure Systems and Software
Requirement overview · 19 controls
6.1
| Control | What it requires | Guidance |
|---|---|---|
| 6.1.1 | All security policies and operational procedures that are identified in Requirement 6… | Yes |
| 6.1.2 | Roles and responsibilities for performing activities in Requirement 6 are documented, assigned… | Yes |
6.2
| Control | What it requires | Guidance |
|---|---|---|
| 6.2.1 | Bespoke and custom software are developed securely… | Yes |
| 6.2.2 | Software development personnel working on bespoke and custom software are trained at least once… | Yes |
| 6.2.3 | Bespoke and custom software is reviewed prior to being released into production… | Yes |
| 6.2.3.1 | If manual code reviews are performed for bespoke and custom software prior to release… | Yes |
| 6.2.4 | Software engineering techniques or other methods are defined and in use by software development… | Yes |
6.3
| Control | What it requires | Guidance |
|---|---|---|
| 6.3.1 | Security vulnerabilities are identified and managed… | Yes |
| 6.3.2 | An inventory of bespoke and custom software, and third-party software components incorporated… | Yes |
| 6.3.3 | All system components are protected from known vulnerabilities by installing applicable… | Yes |
6.4
| Control | What it requires | Guidance |
|---|---|---|
| 6.4.1 | For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing… | Yes |
| 6.4.2 | For public-facing web applications, an automated technical solution is deployed… | Yes |
| 6.4.3 | All payment page scripts that are loaded and executed in the consumer’s browser… | Yes |
6.5
| Control | What it requires | Guidance |
|---|---|---|
| 6.5.1 | Changes to all system components in the production environment are made according… | Yes |
| 6.5.2 | Upon completion of a significant change, all applicable PCI DSS requirements are confirmed… | Yes |
| 6.5.3 | Pre-production environments are separated from production environments and the separation… | Yes |
| 6.5.4 | Roles and functions are separated between production and pre-production environments to provide… | Yes |
| 6.5.5 | Live PANs are not used in pre-production environments… | Yes |
| 6.5.6 | Test data and test accounts are removed from system components before the system goes into… | Yes |
Requirement 7: Restrict Access to System Components and Cardholder Data by Business Need to Know
Requirement overview · 12 controls
7.1
| Control | What it requires | Guidance |
|---|---|---|
| 7.1.1 | All security policies and operational procedures that are identified in Requirement 7… | Yes |
| 7.1.2 | Roles and responsibilities for performing activities in Requirement 7 are documented, assigned… | Yes |
7.2
| Control | What it requires | Guidance |
|---|---|---|
| 7.2.1 | An access control model is defined and includes granting access… | Yes |
| 7.2.2 | Access is assigned to users, including privileged users, based… | Yes |
| 7.2.3 | Required privileges are approved by authorized personnel | Yes |
| 7.2.4 | All user accounts and related access privileges, including third-party/vendor accounts… | Yes |
| 7.2.5 | All application and system accounts and related access privileges are assigned and managed… | Yes |
| 7.2.5.1 | All access by application and system accounts and related access privileges are reviewed… | Yes |
| 7.2.6 | All user access to query repositories of stored cardholder data is restricted… | Yes |
7.3
| Control | What it requires | Guidance |
|---|---|---|
| 7.3.1 | An access control system(s) is in place that restricts access based on a user’s need to know… | Yes |
| 7.3.2 | The access control system(s) is configured to enforce permissions assigned to individuals… | Yes |
| 7.3.3 | The access control system(s) is set to “deny all” by default | Yes |
Requirement 8: Identify Users and Authenticate Access to System Components
Requirement overview · 29 controls
8.1
| Control | What it requires | Guidance |
|---|---|---|
| 8.1.1 | All security policies and operational procedures that are identified in Requirement 8… | Yes |
| 8.1.2 | Roles and responsibilities for performing activities in Requirement 8 are documented, assigned… | Yes |
8.2
| Control | What it requires | Guidance |
|---|---|---|
| 8.2.1 | All users are assigned a unique ID before access to system components or cardholder data… | Yes |
| 8.2.2 | Group, shared, or generic IDs, or other shared authentication credentials are only used… | Yes |
| 8.2.3 | Service providers with remote access to customer premises use unique authentication factors… | Yes |
| 8.2.4 | Addition, deletion, and modification of user IDs, authentication factors… | Yes |
| 8.2.5 | Access for terminated users is immediately revoked | Yes |
| 8.2.6 | Inactive user accounts are removed or disabled within 90 days of inactivity | Yes |
| 8.2.7 | Accounts used by third parties to access, support… | Yes |
| 8.2.8 | If a user session has been idle for more than 15 minutes… | Yes |
8.3
| Control | What it requires | Guidance |
|---|---|---|
| 8.3.1 | All user access to system components for users and administrators is authenticated via at least… | Yes |
| 8.3.2 | Strong cryptography is used to render all authentication factors unreadable during transmission… | Yes |
| 8.3.3 | User identity is verified before modifying any authentication factor | Yes |
| 8.3.4 | Invalid authentication attempts are limited… | Yes |
| 8.3.5 | If passwords/passphrases are used as authentication factors to meet Requirement 8.3.1, they are set and reset for each user… | Yes |
| 8.3.6 | If passwords/passphrases are used as authentication factors to meet Requirement 8.3.1, they meet the following minimum level of complexity… | Yes |
| 8.3.7 | Individuals are not allowed to submit a new password/passphrase that is the same as any… | Yes |
| 8.3.8 | Authentication policies and procedures are documented and communicated to all users… | Yes |
| 8.3.9 | If passwords/passphrases are used as the only authentication factor for user access… | Yes |
| 8.3.10 | Service providers: If passwords/passphrases are used as the only authentication factor for customer user access to cardholder data (i.e., in any single-factor authentication implementation), then guidance is provided to customer users… | Yes |
| 8.3.10.1 | Service providers: If passwords/passphrases are used as the only authentication factor for customer user access (i.e., in any single-factor authentication implementation) then either… | Yes |
| 8.3.11 | Where authentication factors such as physical or logical security tokens, smart cards… | Yes |
8.4
| Control | What it requires | Guidance |
|---|---|---|
| 8.4.1 | MFA is implemented for all non-console access into the CDE for personnel with administrative… | Yes |
| 8.4.2 | MFA is implemented for all non-console access into the CDE | Yes |
| 8.4.3 | MFA is implemented for all remote access originating from outside the entity’s network… | Yes |
8.5
| Control | What it requires | Guidance |
|---|---|---|
| 8.5.1 | MFA systems… | Yes |
8.6
| Control | What it requires | Guidance |
|---|---|---|
| 8.6.1 | If accounts used by systems or applications can be used for interactive login, they… | Yes |
| 8.6.2 | Passwords/passphrases for any application and system accounts that can be used for interactive… | Yes |
| 8.6.3 | Passwords/passphrases for any application and system accounts are protected against misuse… | Yes |
Requirement 9: Restrict Physical Access to Cardholder Data
Requirement overview · 26 controls
9.1
| Control | What it requires | Guidance |
|---|---|---|
| 9.1.1 | All security policies and operational procedures that are identified in Requirement 9… | Yes |
| 9.1.2 | Roles and responsibilities for performing activities in Requirement 9 are documented, assigned… | Yes |
9.2
| Control | What it requires | Guidance |
|---|---|---|
| 9.2.1 | Appropriate facility entry controls are in place to restrict physical access to systems… | Yes |
| 9.2.1.1 | Individual physical access to sensitive areas within the CDE is monitored with either video… | Yes |
| 9.2.2 | Physical and/or logical controls are implemented to restrict use of publicly accessible network… | Yes |
| 9.2.3 | Physical access to wireless access points, gateways, networking/communications hardware… | Yes |
| 9.2.4 | Access to consoles in sensitive areas is restricted via locking when not in use | Yes |
9.3
| Control | What it requires | Guidance |
|---|---|---|
| 9.3.1 | Procedures are implemented for authorizing and managing physical access of personnel… | Yes |
| 9.3.1.1 | Physical access to sensitive areas within the CDE for personnel is controlled… | Yes |
| 9.3.2 | Procedures are implemented for authorizing and managing visitor access to the CDE… | Yes |
| 9.3.3 | Visitor badges or identification are surrendered or deactivated before visitors leave… | Yes |
| 9.3.4 | Visitor logs are used to maintain a physical record of visitor activity both within… | Yes |
9.4
| Control | What it requires | Guidance |
|---|---|---|
| 9.4.1 | All media with cardholder data is physically secured | Yes |
| 9.4.1.1 | Offline media backups with cardholder data are stored in a secure location | Yes |
| 9.4.1.2 | The security of the offline media backup location(s) with cardholder data is reviewed at least… | Yes |
| 9.4.2 | All media with cardholder data is classified in accordance with the sensitivity of the data | Yes |
| 9.4.3 | Media with cardholder data sent outside the facility is secured… | Yes |
| 9.4.4 | Management approves all media with cardholder data that is moved outside the facility… | Yes |
| 9.4.5 | Inventory logs of all electronic media with cardholder data are maintained | Yes |
| 9.4.5.1 | Inventories of electronic media with cardholder data are conducted at least once every 12 months | Yes |
| 9.4.6 | Hard-copy materials with cardholder data are destroyed when no longer needed for business… | Yes |
| 9.4.7 | Electronic media with cardholder data is destroyed when no longer needed for business or legal… | Yes |
9.5
| Control | What it requires | Guidance |
|---|---|---|
| 9.5.1 | POI devices that capture payment card data via direct physical interaction with the payment… | Yes |
| 9.5.1.1 | An up-to-date list of POI devices is maintained… | Yes |
| 9.5.1.2 | POI device surfaces are periodically inspected to detect tampering and unauthorized substitution | Yes |
| 9.5.1.3 | Training is provided for personnel in POI environments to be aware of attempted tampering… | Yes |
Requirement 10: Log and Monitor All Access to System Components and Cardholder Data
Requirement overview · 27 controls
10.1
| Control | What it requires | Guidance |
|---|---|---|
| 10.1.1 | All security policies and operational procedures that are identified in Requirement 10… | Yes |
| 10.1.2 | Roles and responsibilities for performing activities in Requirement 10 are documented… | Yes |
10.2
| Control | What it requires | Guidance |
|---|---|---|
| 10.2.1 | Audit logs are enabled and active for all system components and cardholder data | Yes |
| 10.2.1.1 | Audit logs capture all individual user access to cardholder data | Yes |
| 10.2.1.2 | Audit logs capture all actions taken by any individual with administrative access… | Yes |
| 10.2.1.3 | Audit logs capture all access to audit logs | Yes |
| 10.2.1.4 | Audit logs capture all invalid logical access attempts | Yes |
| 10.2.1.5 | Audit logs capture all changes to identification and authentication credentials… | Yes |
| 10.2.1.6 | Audit logs capture… | Yes |
| 10.2.1.7 | Audit logs capture all creation and deletion of system-level objects | Yes |
| 10.2.2 | Audit logs record the following details for each auditable event… | Yes |
10.3
| Control | What it requires | Guidance |
|---|---|---|
| 10.3.1 | Read access to audit logs files is limited to those with a job-related need | Yes |
| 10.3.2 | Audit log files are protected to prevent modifications by individuals | Yes |
| 10.3.3 | Audit log files, including those for external-facing technologies… | Yes |
| 10.3.4 | File integrity monitoring or change-detection mechanisms is used on audit logs to ensure… | Yes |
10.4
| Control | What it requires | Guidance |
|---|---|---|
| 10.4.1 | The following audit logs are reviewed at least once daily… | Yes |
| 10.4.1.1 | Automated mechanisms are used to perform audit log reviews | Yes |
| 10.4.2 | Logs of all other system components (those not specified in Requirement 10.4.1) are reviewed… | Yes |
| 10.4.2.1 | The frequency of periodic log reviews for all other system components… | Yes |
| 10.4.3 | Exceptions and anomalies identified during the review process are addressed | Yes |
10.5
| Control | What it requires | Guidance |
|---|---|---|
| 10.5.1 | Retain audit log history for at least 12 months, with at least the most recent three months… | Yes |
10.6
| Control | What it requires | Guidance |
|---|---|---|
| 10.6.1 | System clocks and time are synchronized using time-synchronization technology | Yes |
| 10.6.2 | Systems are configured to the correct and consistent time… | Yes |
| 10.6.3 | Time synchronization settings and data are protected… | Yes |
10.7
| Control | What it requires | Guidance |
|---|---|---|
| 10.7.1 | Service providers: Failures of critical security control systems are detected, alerted, and addressed promptly… | Yes |
| 10.7.2 | Failures of critical security control systems are detected, alerted, and addressed promptly… | Yes |
| 10.7.3 | Failures of any critical security control systems are responded to promptly… | Yes |
Requirement 11: Test Security of Systems and Networks Regularly
Requirement overview · 21 controls
11.1
| Control | What it requires | Guidance |
|---|---|---|
| 11.1.1 | All security policies and operational procedures that are identified in Requirement 11… | Yes |
| 11.1.2 | Roles and responsibilities for performing activities in Requirement 11 are documented… | Yes |
11.2
| Control | What it requires | Guidance |
|---|---|---|
| 11.2.1 | Authorized and unauthorized wireless access points… | Yes |
| 11.2.2 | An inventory of authorized wireless access points is maintained… | Yes |
11.3
| Control | What it requires | Guidance |
|---|---|---|
| 11.3.1 | Internal vulnerability scans… | Yes |
| 11.3.1.1 | All other applicable vulnerabilities… | Yes |
| 11.3.1.2 | Internal vulnerability scans are performed via authenticated scanning… | Yes |
| 11.3.1.3 | Internal vulnerability scans are performed after any significant change… | Yes |
| 11.3.2 | External vulnerability scans… | Yes |
| 11.3.2.1 | External vulnerability scans are performed after any significant change… | Yes |
11.4
| Control | What it requires | Guidance |
|---|---|---|
| 11.4.1 | A penetration testing methodology is defined, documented, and implemented by the entity… | Yes |
| 11.4.2 | Internal penetration testing is performed… | Yes |
| 11.4.3 | External penetration testing is performed… | Yes |
| 11.4.4 | Exploitable vulnerabilities and security weaknesses found during penetration testing… | Yes |
| 11.4.5 | If segmentation is used to isolate the CDE from other networks… | Yes |
| 11.4.6 | Service providers: If segmentation is used to isolate the CDE from other networks… | Yes |
| 11.4.7 | Multi-tenant service providers support their customers for external penetration testing per… | Yes |
11.5
| Control | What it requires | Guidance |
|---|---|---|
| 11.5.1 | Intrusion-detection and/or intrusion-prevention techniques are used to detect and/or prevent… | Yes |
| 11.5.1.1 | Service providers: Intrusion-detection and/or intrusion-prevention techniques detect, alert on/prevent… | Yes |
| 11.5.2 | A change-detection mechanism (for example, file integrity monitoring tools)… | Yes |
11.6
| Control | What it requires | Guidance |
|---|---|---|
| 11.6.1 | A change- and tamper-detection mechanism… | Yes |
Requirement 12: Support Information Security with Organizational Policies and Programs
Requirement overview · 37 controls
12.1
| Control | What it requires | Guidance |
|---|---|---|
| 12.1.1 | An overall information security policy… | Yes |
| 12.1.2 | The information security policy… | Yes |
| 12.1.3 | The security policy clearly defines information security roles and responsibilities for all… | Yes |
| 12.1.4 | Responsibility for information security is formally assigned to a Chief Information Security… | Yes |
12.2
| Control | What it requires | Guidance |
|---|---|---|
| 12.2.1 | Acceptable use policies for end-user technologies are documented and implemented… | Yes |
12.3
| Control | What it requires | Guidance |
|---|---|---|
| 12.3.1 | For each PCI DSS requirement that specifies completion of a targeted risk analysis… | Yes |
| 12.3.2 | A targeted risk analysis is performed for each PCI DSS requirement that the entity meets… | Yes |
| 12.3.3 | Cryptographic cipher suites and protocols in use are documented and reviewed at least once… | Yes |
| 12.3.4 | Hardware and software technologies in use are reviewed at least once every 12 months… | Yes |
12.4
| Control | What it requires | Guidance |
|---|---|---|
| 12.4.1 | Service providers: Responsibility is established by executive management for the protection of cardholder data… | Yes |
| 12.4.2 | Service providers: Reviews are performed at least once every three months to confirm that personnel are performing… | Yes |
| 12.4.2.1 | Service providers: Reviews conducted in accordance with Requirement 12.4.2 are documented… | Yes |
12.5
| Control | What it requires | Guidance |
|---|---|---|
| 12.5.1 | An inventory of system components that are in scope for PCI DSS… | Yes |
| 12.5.2 | PCI DSS scope is documented and confirmed by the entity at least once every 12 months and upon… | Yes |
| 12.5.2.1 | Service providers: PCI DSS scope is documented and confirmed by the entity at least once every six months and upon… | Yes |
| 12.5.3 | Service providers: Significant changes to organizational structure result in a documented (internal) review… | Yes |
12.6
| Control | What it requires | Guidance |
|---|---|---|
| 12.6.1 | A formal security awareness program is implemented to make all personnel aware of the entity’s… | Yes |
| 12.6.2 | The security awareness program… | Yes |
| 12.6.3 | Personnel receive security awareness training… | Yes |
| 12.6.3.1 | Security awareness training includes awareness of threats and vulnerabilities that could impact… | Yes |
| 12.6.3.2 | Security awareness training includes awareness about the acceptable use of end-user… | Yes |
12.7
| Control | What it requires | Guidance |
|---|---|---|
| 12.7.1 | Potential personnel who will have access to the CDE are screened… | Yes |
12.8
| Control | What it requires | Guidance |
|---|---|---|
| 12.8.1 | A list of all third-party service providers (TPSPs) with which account data is shared… | Yes |
| 12.8.2 | Written agreements with TPSPs are maintained… | Yes |
| 12.8.3 | An established process is implemented for engaging TPSPs… | Yes |
| 12.8.4 | A program is implemented to monitor TPSPs’ PCI DSS compliance status at least once every 12… | Yes |
| 12.8.5 | Information is maintained about which PCI DSS requirements are managed by each TPSP… | Yes |
12.9
| Control | What it requires | Guidance |
|---|---|---|
| 12.9.1 | Service providers: TPSPs provide written agreements to customers that include acknowledgments that TPSPs… | Yes |
| 12.9.2 | Service providers: TPSPs support their customers’ requests for information to meet Requirements 12.8.4 and 12.8.5… | Yes |
12.10
| Control | What it requires | Guidance |
|---|---|---|
| 12.10.1 | An incident response plan exists and is ready to be activated in the event of a suspected… | Yes |
| 12.10.2 | At least once every 12 months, the security incident response plan… | Yes |
| 12.10.3 | Specific personnel are designated to be available on a 24/7 basis to respond to suspected… | Yes |
| 12.10.4 | Personnel responsible for responding to suspected and confirmed security incidents… | Yes |
| 12.10.4.1 | The frequency of periodic training for incident response personnel is defined in the entity’s… | Yes |
| 12.10.5 | The security incident response plan includes monitoring and responding to alerts from security… | Yes |
| 12.10.6 | The security incident response plan is modified and evolved according to lessons learned… | Yes |
| 12.10.7 | Incident response procedures are in place, to be initiated upon the detection of stored PAN… | Yes |
Source
Control identifiers, requirement text and testing procedures are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. Download the standard from the PCI Security Standards Council document library.