PCI DSS 12.6.3.1: Security awareness training includes awareness of threats and vulnerabilities that could impact
PCI DSS v4.0.1 control 12.6.3.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.6.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.6
Security awareness training includes awareness of threats and vulnerabilities that could impact the security of cardholder data and/or sensitive authentication data, including but not limited to:
- Phishing and related attacks.
- Social engineering.
Summary
Security awareness training covers the threats that actually reach people: phishing and social engineering.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.6.3.1 | Examine security awareness training content to verify it includes all elements specified in this requirement. |
Specific where the rest of 12.6.3 is general. Training must include awareness of threats and vulnerabilities that could impact the security of cardholder data and/or sensitive authentication data, and the requirement names two: phishing and related attacks, and social engineering. They are named because they are how compromises usually begin, and because they target people rather than systems, which is what makes training the control rather than a supplement to one. Note the relationship with 5.4.1, which requires processes and automated mechanisms against phishing: the standard states explicitly that meeting one does not meet the other. Technical anti-phishing controls and human awareness are separate requirements, and an entity with excellent mail filtering still has to train.
What to prepare
- Training content, checked for both named topics.
- Evidence the content is current, since these threats change.
- Delivery records showing who received it.
- The relationship to 5.4.1, which is a different control.
How to implement it
1. Use current examples. Phishing awareness built on examples from several years ago teaches people to spot attacks nobody is sending, and the credible ones now look like ordinary business email.
2. Cover social engineering beyond email. Phone calls and in-person approaches are the route in 9.5.1.3, where someone in a uniform asks for access to a terminal.
3. Do not let 5.4.1 substitute. The standard says so directly, and an entity that points at its mail filtering has answered a different requirement.
4. Make reporting the outcome. Awareness that ends in recognition and not in a report leaves the organisation no better informed.
Where this commonly fails
- Generic security training with no phishing or social engineering content.
- Technical anti-phishing controls offered in place of training.
- Examples that are years out of date and unlike current attacks.
- Training that teaches recognition without giving people somewhere to report.
Related controls
Others in section 12.6:
| Control | What it requires |
|---|---|
| 12.6.1 | A formal security awareness program is implemented to make all personnel aware of the entity’s… |
| 12.6.2 | The security awareness program… |
| 12.6.3 | Personnel receive security awareness training… |
| 12.6.3.2 | Security awareness training includes awareness about the acceptable use of end-user… |
← 12.6.3 · All controls · 12.6.3.2 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.