Support information security with policies
Requirement 12 requires organizations to establish, document, and maintain a formal information security policy that defines the organization's approach to protecting cardholder data. This ensures that security is managed as a corporate mandate rather than an ad-hoc technical effort, with policies reviewed annually and communicated to all relevant personnel.
What it means
In practice, this requirement serves as the governance layer for the rest of PCI DSS. While other requirements focus on technical controls (like firewalls or encryption), Requirement 12 ensures there is a written "law of the land" that mandates those controls be implemented and maintained consistently across the organization.
The scope extends to all employees, contractors, and third parties who have access to the Cardholder Data Environment (CDE). It transforms security from a set of tasks into an organizational obligation, ensuring that leadership has formally approved the security strategy and that staff are aware of their responsibilities.
How to meet it
- Create a comprehensive Information Security Policy (ISP) that addresses all PCI DSS requirements applicable to your environment.
- Define clear roles and responsibilities for personnel managing security tasks to ensure accountability.
- Establish a formal process to review the policy at least once every 12 months or upon significant changes to the network/environment.
- Implement a distribution mechanism, such as a company intranet or employee handbook, to make policies accessible to all relevant staff.
- Require employees and contractors to formally acknowledge that they have read and understood the security policies during onboarding and annually thereafter.
Evidence an auditor asks for
- The current Information Security Policy document, including version history and approval dates.
- Signed acknowledgments or digital logs proving that all personnel with CDE access have reviewed the policy.
- Documented evidence of the most recent annual policy review (e.g., meeting minutes or a sign-off from management).
- Organizational charts or job descriptions that explicitly map security responsibilities to specific roles.
Common pitfalls
- "Shelfware": Maintaining a polished policy document that does not actually reflect how the organization operates in reality.
- Generic Templates: Using an unedited industry template that references controls or departments that do not exist within the company.
- Communication Gaps: Having a documented policy but failing to produce evidence (like signatures) that employees were actually notified of it.