PCI DSS 12.6.2: The security awareness program

PCI DSS v4.0.1 control 12.6.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.6.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.6

The security awareness program is:

  • Reviewed at least once every 12 months, and
  • Updated as needed to address any new threats and vulnerabilities that may impact the security of the entity’s cardholder data and/or sensitive authentication data, or the information provided to personnel about their role in protecting cardholder data.

Summary

Review the awareness programme at least yearly and update it when the threats or your environment change.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.6.2 Examine security awareness program content, evidence of reviews, and interview personnel to verify that the security awareness program is in accordance with all elements specified in this requirement.

The maintenance obligation behind 12.6.1 and 12.6.3. The single procedure examines the programme and the review records, and the word carrying the weight is updated as needed: a review that concludes "no change" every year, while the threat landscape and the business both moved, is a review in name. This is the control that keeps awareness content from describing a payment channel you no longer operate, or omitting the phishing pattern that actually reached your staff last quarter.

What to prepare

  • Dated review records, with who reviewed and what changed.
  • The programme’s version history, showing content actually changed.
  • The inputs considered: incidents, phishing results, new channels, new providers.

How to implement it

1. Feed real events into the review. An incident, a near miss or a phishing simulation result is the most defensible input, and it makes the update obvious rather than invented.

2. Review after a change to the payment environment, not only annually. A new channel or a new provider changes what staff need to know, and content describing the old arrangement is worse than generic.

3. Record the reasoning when nothing changes. "Reviewed, no change" is acceptable if you can say what was considered; unexplained it looks like the review did not happen.

4. Keep the version history. It is the cheapest evidence that the programme is maintained rather than written once.

Where this commonly fails

  • A review recorded annually with content untouched for years.
  • Content still describing a channel or provider the business has left.
  • Phishing simulation results collected and never used to shape the training.
  • No named owner, so the review happens when an assessment is booked.

Others in section 12.6:

Control What it requires
12.6.1 A formal security awareness program is implemented to make all personnel aware of the entity’s…
12.6.3 Personnel receive security awareness training…
12.6.3.1 Security awareness training includes awareness of threats and vulnerabilities that could impact…
12.6.3.2 Security awareness training includes awareness about the acceptable use of end-user…

12.6.1 · All controls · 12.6.3

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.