PCI DSS · Domain 6
Security Policy
About 15% of the exam
Requirement 12 duties
- 12.1
- security policy established and maintained
- 12.2
- acceptable use for end user technologies
- 12.3
- risks formally identified and managed
- 12.4
- compliance actively managed and overseen
- 12.5
- scope documented and validated regularly
- 12.6
- security awareness education program
- 12.7
- personnel screened before hire
- 12.8
- third party provider risk managed
- 12.9
- providers support customer compliance
- 12.10
- incident response readiness maintained
The policy is reviewed at least every twelve months and updated whenever the environment or the risk changes
Defined versus customized approach
- Defined approach
- meet the requirement as written
- Customized approach
- meet the stated objective differently
- Objective
- what each requirement is meant to achieve
- Targeted risk analysis
- mandatory before customizing anything
- Controls matrix
- the entity documents its own control
- Assessor duty
- derive and perform bespoke testing
- Compensating controls
- defined approach only, never customized
- Eligibility
- some requirements cannot be customized
Compensating controls belong to the defined approach; the customized approach changes the method, never the outcome required
Targeted risk analysis
- Required for every customized control
- Also required for flexible frequencies
- Documents assets, threats and likelihood
- States the chosen frequency and why
- Reviewed at least every twelve months
- Approved by senior management
Validation documents
- SAQ
- self assessment for eligible entities
- ROC
- report on compliance from an assessment
- AOC
- attestation signed by the entity
- Compensating worksheet
- records constraint, objective and control
- Customized documents
- objective, analysis and testing evidence
- Requirement status
- in place, not applicable, not tested
Who assesses
- QSA
- qualified assessor from an approved firm
- ISA
- internal assessor trained and certified
- ASV
- approved vendor for external scanning
- Forensic investigator
- engaged after a suspected breach
- Merchant level
- set by annual transaction volume
- Acquirer
- decides what validation you owe
Policy content
- Published, disseminated and acknowledged
- Roles and responsibilities defined explicitly
- Acceptable use of end user technologies
- Remote access and wireless rules
- Exception process with approval and expiry
- Reviewed and updated every twelve months
Awareness program
- Training at hire and annually
- Covers phishing and social engineering
- Covers acceptable use of technologies
- Tailored to the role performed
- Acknowledged and recorded per person
- Content reviewed at least annually
Third party management
- Maintain a list of all providers
- Written agreements acknowledging their responsibility
- Due diligence before engagement
- Compliance status monitored at least annually
- Responsibility matrix agreed per provider
- Providers must support customer requests
Scope duties in 12.5
- Inventory of in scope components
- Scope confirmed every twelve months
- Service providers confirm every six months
- Significant organizational change triggers review
- Documented and available to the assessor
The compliance year
- Confirm scope
- Remediate known gaps
- Run scans and tests
- Gather evidence
- Assessment fieldwork
- Resolve findings
- Sign the attestation
- Submit to the acquirer
- Evidence gathered all year, not one week
- Validation is a point in time snapshot
- Controls must operate the whole year
- Interim changes reassessed by the assessor
Policy and program failures
- Policy last reviewed three years ago
- Training delivered without any acknowledgment
- Provider list missing the newest vendors
- Responsibility matrix never agreed with providers
- Exceptions granted with no expiry date
- Risk analysis written to justify a decision
- Incident plan never actually exercised
What version 4.0 changed here
- Customized approach added beside the defined one
- Targeted risk analysis formalized as a document
- Executive responsibility explicit for service providers
- Quarterly personnel reviews for service providers
- Scope validation more frequent for providers
- Roles and responsibilities named per requirement
- Future dated items became mandatory in 2025
Rapid recall: SAQ types
- SAQ A
- fully outsourced card not present
- SAQ A-EP
- ecommerce site affecting the payment
- SAQ B
- imprint or standalone dial out terminals
- SAQ B-IP
- standalone terminals using internet protocol
- SAQ C
- payment application connected to internet
- SAQ C-VT
- virtual terminal on one computer
- SAQ P2PE
- validated encryption terminals only
- SAQ D
- everyone else, merchants and providers
Reporting words
- Compliance
- validated at a point in time
- Not tested
- excluded from this assessment
- Not applicable
- the requirement cannot apply here
- Not in place
- the requirement failed at assessment
- Remediation
- fix, then reassess the requirement
Reference strip: policy, people, providers, approach, reporting
Policy
- Published and acknowledged
- Reviewed every twelve months
- Exceptions approved and expiring
People
- Screened before hire
- Trained at hire and yearly
- Roles named per requirement
Providers
- Listed with written agreements
- Due diligence before engagement
- Responsibility matrix agreed
Approach
- Defined follows the wording
- Customized meets the objective
- Targeted risk analysis required
Reporting
- SAQ or ROC as required
- Attestation signed by the entity
- Acquirer decides the obligation
Quick exam traps
- Trap: The customized approach and compensating controls are the same mechanism
- Trap: A signed attestation proves controls operated all year
- Trap: Requirement 12 is paperwork with no technical consequence
- Trap: Any requirement may be met through the customized approach
- Trap: An SAQ can be chosen freely by the merchant
- Trap: Outsourcing payment processing removes third party management duties
- Trap: The policy only needs updating when the standard changes
cybercertprep.com · original revision sheet written from the public body of knowledge