PCI DSS 12.2.1: Acceptable use policies for end-user technologies are documented and implemented
PCI DSS v4.0.1 control 12.2.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.2.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.2
Acceptable use policies for end-user technologies are documented and implemented, including:
- Explicit approval by authorized parties.
- Acceptable uses of the technology.
- List of products approved by the company for employee use, including hardware and software.
Summary
Write down what end-user technologies people may use and how, including which products are approved.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.2.1 | Examine the acceptable use policies for end-user technologies and interview responsible personnel to verify processes are documented and implemented in accordance with all elements specified in this requirement. |
Three elements, and the third is the one entities have not written: a list of products approved by the company for employee use, including hardware and software. Acceptable use policies usually describe behaviour well and stop short of naming what may be used, which leaves the policy unable to answer the question it exists for. The other two are explicit approval by authorized parties and acceptable uses of the technology. This is also the control that makes shadow IT a compliance question rather than only an operational one: an approved-products list turns "someone signed up for a file-sharing service" into a policy breach that can be identified. It is reinforced by 12.6.3.2, which requires acceptable use to be covered in security awareness training.
What to prepare
- The acceptable use policy, checked against all three elements.
- The approved product list for hardware and software, current.
- Evidence of approval by an authorised party.
- How the list is maintained as products are added or retired.
How to implement it
1. Write the product list, since it is the missing element. It does not need to be exhaustive to be useful: naming the approved categories and the specific products within them is what makes it maintainable.
2. Say who approves, and record their approval. The first element is explicit approval by authorised parties, which needs a name behind it.
3. Cover personal devices deliberately, since 1.5.1 already brings employee-owned devices into scope where they reach the CDE.
4. Connect it to the training in 12.6.3.2. A policy people have not been taught is a policy nobody follows.
Where this commonly fails
- A well-written acceptable use policy with no approved product list.
- A product list maintained by procurement and unknown to the policy.
- Cloud services omitted, though they are software the employee uses.
- No named approver, so approval cannot be evidenced.
Related controls
← 12.1.4 · All controls · 12.3.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.