PCI DSS 12.1.1: An overall information security policy
PCI DSS v4.0.1 control 12.1.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.1.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.1
An overall information security policy is:
- Established.
- Published.
- Maintained.
- Disseminated to all relevant personnel, as well as to relevant vendors and business partners.
Summary
There is an information security policy, it is current, and the people it applies to have actually received it.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.1.1 | Examine the information security policy and interview personnel to verify that the overall information security policy is managed in accordance with all elements specified in this requirement. |
The root of Requirement 12 and the document most other policies hang from. Four verbs, and the last two are where entities fall short: established and published are easy, maintained and disseminated are ongoing. Dissemination explicitly extends to relevant vendors and business partners, not only staff, which is the element most often missed entirely. It is also the policy that 12.6.1 makes personnel aware of and that 12.6.3 asks them to acknowledge, so a policy nobody has read fails three controls at once.
What to prepare
- The policy itself, with a version and a review date.
- Evidence of dissemination to personnel, and separately to vendors and partners.
- The annual review record required by 12.1.2.
How to implement it
1. Put the review date in the document. It is the cheapest evidence of "maintained" and the first thing an assessor looks for.
2. Disseminate to third parties deliberately. Attaching the relevant policy to supplier onboarding is the practical route, and it is the element most entities have no evidence for at all.
3. Keep it short enough to be read. A policy that is disseminated and not understood fails the awareness controls that depend on it, and length is the usual reason.
4. Link the acknowledgement. 12.6.3 asks personnel to confirm they have read and understood this document, so the acknowledgement should name the version.
Where this commonly fails
- Published on an intranet page with no evidence anyone was directed to it.
- Vendors and business partners omitted from dissemination, though they are named.
- A policy dated years ago with no review record.
- Acknowledgements collected against a version that has since changed materially.
Related controls
Others in section 12.1:
| Control | What it requires |
|---|---|
| 12.1.2 | The information security policy… |
| 12.1.3 | The security policy clearly defines information security roles and responsibilities for all… |
| 12.1.4 | Responsibility for information security is formally assigned to a Chief Information Security… |
← 11.6.1 · All controls · 12.1.2 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.