Requirement 12: Support Information Security with Organizational Policies and Programs
Everything the other eleven requirements assume: policy, risk analysis, awareness, third parties, incident response. v4 moved real weight here — targeted risk analyses now justify half the standard’s frequencies, and scope must be confirmed annually in writing.
Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series
The controls that decide your assessment
Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.
Where programmes actually fail
12.8.5 wants, per provider, which requirements they cover vs you — an AOC on file alone does not answer it.
Choosing "weekly" for a flexible control without the TRA behind it fails 12.3.1 across every control that leaned on it.
The annual scope confirmation (12.5.2) needs a dated artefact: data flows, people, processes, technologies, third parties.
A tabletop with attendance, scenario and lessons-learned is the minimum evidence for 12.10.2 — an unopened PDF is not a capability.
Evidence a QSA accepts
A policy document proves intent; configuration proves control. Bring these to the assessment:
- Policy set with review dates and management approval
- The TRA collection: one per flexible-frequency control in use
- Annual scope-confirmation document with data flows and third parties
- Awareness records: content incl. phishing, completion, acknowledgements
- TPSP register: agreements, AOCs, responsibility matrices, annual checks
- IR plan + most recent test records and post-incident lessons
Requirement 12 FAQ
What is a targeted risk analysis (TRA)?
A documented analysis (per 12.3.1) that justifies how frequently you perform a flexible-frequency control — identifying the assets and threats, and why the chosen cadence keeps risk acceptable.
How do we evidence third-party compliance?
Annually confirm each TPSP’s PCI DSS status (their AOC or equivalent), keep written agreements with responsibility acknowledgements (12.8.2/12.9), and maintain a shared responsibility matrix (12.8.5).
How often must incident response be tested?
At least annually (12.10.2), with training for responders and a plan that includes card-brand/regulator notification and the v4 addition: what to do when PAN turns up where it should not be (12.10.7).
Requirement 12 in your environment
A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.
