February 26, 2024

PCI DSS Requirement 12: What Is It and How to Comply?

PCI DSS requirement 12 requests that businesses maintain a policy that addresses information security for all relevant personnel. This policy should address the proper use of all systems and networks, as well as information security incident response procedures.

By
Full name
Share this post
https://www.hicomply.com/hub/pci-dss-requirement-12
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

By creating a strong information security policy, your business can emphasise the critical nature of protecting cardholder data – minimising the risk of any vulnerabilities occurring internally.

{{snapshot}}

The information security policy

  • Establish, publish, and circulate an information security policy to all personnel, vendors, and business partners.
  • Review it at least annually and define roles and responsibilities everyone understands.
  • Assign overall responsibility to a CISO or other member of upper management.

{{/snapshot}}

PCI DSS Requirement 12.1: A comprehensive information security policy on information protection should be implemented and maintained.

Your business should implement an information security policy that communicates higher management’s intent and objectives regarding the protection of security systems, particularly cardholder data.

The sub-sub-requirements of this section include:

  • PCI DSS Requirement 12.1.1: An information security policy is established, published, maintained, and circulated to all necessary personnel, relevant vendors and business partners.
  • PCI DSS Requirement 12.1.2: The information security policy must be reviewed at a minimum, annually, and updated where necessary.
  • PCI DSS Requirement 12.1.3: The policy must define roles and responsibilities for all personnel, and all personnel are aware of and understand their duties.
  • PCI DSS Requirement 12.1.4: The responsibility for information security is formally assigned to a Chief Information Security Officer (CISO) or another relevant member of upper management.

PCI DSS Requirement 12.2: Acceptable use policies for end-user technologies need to be defined and put in place.

Businesses should look to invest in end-user technologies, although these must be managed properly to avoid further risks. An acceptable use policy should outline the expected behaviour from relevant personnel when using this technology, reflecting the organisation’s risk tolerance.

{{snapshot}}

Acceptable use and targeted risk

  • Define acceptable use policies for end-user technologies that reflect your risk tolerance.
  • Support each flexible requirement with a targeted risk assessment using a solid methodology.
  • Review cryptographic cipher suites and hardware/software at least annually.

{{/snapshot}}

PCI DSS Requirement 12.3: CDE risks must be formally identified, evaluated, and managed.

Some of the PCI DSS requirements will allow an organisation to decide how often an activity is performed based on the potential risks. Performing a risk assessment according to a solid methodology allows you to remain valid in compliance.

The sub-sub-requirements of this section include:

  • PCI DSS Requirement 12.3.1: Each PCI DSS requirement that provides flexibility for how frequently it is performed should be supported by a targeted risk assessment.
  • PCI DSS Requirement 12.3.2: A targeted risk assessment is performed for each PCI DSS requirement the entity meets with a customised approach.
  • PCI DSS Requirement 12.3.3: Cryptographic cipher suites and protocols must be reviewed at least annually.
  • PCI DSS Requirement 12.3.4: Hardware and software technologies must be reviewed at least annually.

PCI DSS Requirement 12.4: Ensure PCI DSS compliance is managed.

PCI DSS compliance responsibilities must be assigned to a member of higher management to ensure visibility into the process.

{{snapshot}}

Owning and scoping compliance

  • Assign PCI DSS compliance to a member of higher management for visibility.
  • Keep an up-to-date inventory of all system components in scope — nothing excluded.
  • Document and confirm scope at least annually and after any significant change.

{{/snapshot}}

PCI DSS Requirement 12.5: The PCI DSS scope must be documented and validated.

Your organisation must maintain an up-to-date list of all system components to best define the scope of the environment and implement the requirements accurately. The inventory must not exclude any system components to remain compliant.

The sub-sub-requirements of this section include:

  • PCI DSS Requirement 12.5.1: An inventory of all system components that are in scope for PCI DSS, including in-depth descriptions of use, must be updated and maintained.
  • PCI DSS Requirement 12.5.2: The PCI DSS scope is documented and confirmed at least annually and after any significant changes.

{{snapshot}}

Training and screening people

  • Run a formal security awareness program and train all personnel on the policy and procedures.
  • Review the program annually to address new threats and vulnerabilities.
  • Screen new staff who may access the CDE before hire, within local law.

{{/snapshot}}

PCI DSS Requirement 12.6: Staff training on security awareness must be ongoing.

Your staff must receive training, or re-training, if necessary, on their security responsibilities and implemented safeguards and processes to minimise the risk of a breach.

The sub-sub-requirements of this section include:

  • PCI DSS Requirement 12.6.1: A formal security awareness program must be implemented, and all personnel must be aware of the information security policy and procedures.
  • PCI DSS Requirement 12.6.2: The security awareness program must be reviewed annually and updated where necessary to address any new threats and vulnerabilities.
  • PCI DSS Requirement 12.6.3: All personnel must receive security awareness training.

PCI DSS Requirement 12.7: Personnel must be screened to reduce the risk of an insider threat.

New staff members who may need to access the CDE should be thoroughly screened within the constraints of local laws before they are hired to ensure both cardholder and workplace safety.

{{snapshot}}

Managing third-party providers

  • Maintain a list of all TPSPs that handle or could affect account data, with written agreements.
  • Perform due diligence before engagement and review each TPSP’s compliance status at least annually.
  • Document which requirements each TPSP owns, which you own, and which are shared — and only work with compliant TPSPs.

{{/snapshot}}

Requirement 12.8: Third-party service provider (TPSP) relationships should have risks managed.

Creating and maintaining a list of all in-use third-party service providers (TPSPs) will help your business to identify any potential risks outside the organisation. This will also further define your extended attack surface.

The sub-sub-requirements of this section include:

  • PCI DSS Requirement 12.8.1: A list of all in-use TPSPs with which account data is shared or that could affect the security of account data is created and maintained.
  • PCI DSS Requirement 12.8.2: Written agreements with TPSPs are created and maintained.
  • PCI DSS Requirement 12.8.3: An established process is implemented for engaging TPSPs. This must include proper due diligence prior to engagement.
  • PCI DSS Requirement 12.8.4: A program is implemented to review in-use TPSPs’ PCI DSS compliance status at least annually.
  • PCI DSS Requirement 12.8.5: Which PCI DSS requirements are managed by each TPSP must be documented, including which are managed by the business, and any that are shared between the TPSP and the business.

PCI DSS Requirement 12.9: TPSPs must support their customers’ PCI DSS compliance.

Your business should seek to only work with third parties that are careful to achieve and maintain PCI DSS compliance, as this will protect the security of your customers’ cardholder data.

{{snapshot}}

Responding to incidents

  • Keep an incident response plan that can be activated immediately.
  • Review, update, and test the plan annually, with trained responders on-call 24/7.
  • Feed in monitoring alerts and lessons learned, and cover detection of unexpected PAN in storage.

{{/snapshot}}

PCI DSS Requirement 12.10: Any security incidents that could impact the CDE must be understood and addressed immediately.

It's important to put an incident response plan in place for the appropriate personnel, to avoid a missed attack, which could result in financial or reputational loss for your business.

The sub-sub-requirements of this section include:

ControlRequirement
12.10.1An incident response plan is implemented and can be readily activated
12.10.2The plan is reviewed, updated, and tested at least once a year
12.10.3Designated personnel are on-call 24/7 to respond to incidents
12.10.4Those responding to incidents are appropriately trained
12.10.5The plan includes monitoring and responding to alerts from monitoring systems
12.10.6The plan is updated per industry developments and lessons learned
12.10.7Procedures cover detection of unexpected PAN in storage

{{snapshot}}

What Hicomply recommends

Requirement 12 is the governance backbone of PCI DSS — policy, risk, scope, training, third parties, and incident response — and it maps almost one-to-one onto a wider ISMS. We find teams save real effort by running it as part of their ISO 27001 management system rather than a standalone PCI programme, so policies, evidence, and reviews are maintained once and stay audit-ready. A platform tour shows how, and our free compliance tools help you get started.

{{/snapshot}}

Compliance as you work with Hicomply

PCI DSS compliance protects your business from severe financial and reputational loss – however, it can seem quite intimidating due to the long, thorough process. This is why we at Hicomply offer a full-fledged ISMS solution that keeps all your documents in one place – allowing you to focus on your business. Get in touch today to receive a demo.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status. Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Getting Started
Computer Software
IT and Services
Legal Services
Financial Services
Growth