PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.1.1: 12.1.1 Overall information security policy established and disseminated

The organisation must have one overarching information security policy that is formally set up, made available in published form, kept under maintenance, and distributed to every relevant member of personnel and to vendors and business partners who are relevant. The guidance defines 'relevant' as anyone whose role, internal or as an outside provider of services or functions, touches some or all of the topics the policy addresses. The guidance explains that this top-level policy governs the more specific technical and discipline policies beneath it. Objective under the customized approach: the strategic aims and principles of information security are set out, formally adopted, and understood by everyone who works for the entity.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 156 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 21 controls

  • 5.1 General
  • 5.2 Context of the organization
  • 5.2.4 Information security management system
  • 5.3 Leadership
  • 5.3.1 Leadership and commitment
  • 5.3.2 Policy
  • 5.3.3 Organizational roles, responsibilities and authorities
  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.5.1 Resources
  • 5.5.4 Communication
  • 5.6.1 Operational planning and control
  • 6.1 General
  • 6.2 Information security policies
  • 6.2.1 Management direction for information security
  • 6.3 Organization of information security
  • 6.3.1 Internal organization
  • 6.6.3 User responsibilities
  • 6.9.1 Operational procedures and responsibilities
  • 7.1 General
  • 8.1 General

NIST SP 800-53 Rev 5 · 19 controls

ISO 22301:2019 · 18 controls

  • 4.2.2 Legal and regulatory requirements
  • 4.4 Business continuity management system
  • 5.1 Leadership and commitment
  • 5.2 Policy
  • 5.2.1 Establishing the business continuity policy
  • 5.2.2 Communicating the business continuity policy
  • 5.3 Roles, responsibilities and authorities
  • 6.1.1 Determining risks and opportunities
  • 6.3 Planning changes to the business continuity management system
  • 7.1 Resources
  • 7.5 Documented information
  • 7.5.1 General
  • 7.5.2 Creating and updating
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • 8.4.1 General
  • 9.2.1 General
  • 9.3.1 General

ISO/IEC 42001:2023 · 18 controls

  • 4.4 AI management system
  • 5.1 Leadership and commitment
  • 5.2 AI policy
  • 6.1 Actions to address risks and opportunities
  • 6.1.1 General
  • 6.2 AI objectives and planning to achieve them
  • 7.1 Resources
  • 7.3 Awareness
  • 7.4 Communication
  • 7.5 Documented information
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • A.2 Policies related to AI
  • A.2.2 AI policy
  • A.2.3 Alignment with other organizational policies
  • A.3 Internal organization
  • A.4.6 Human resources
  • A.8.5 Information for interested parties

FedRAMP High · 17 controls

  • AC-1 Policy and Procedures
  • AT-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CM-3(4) Security and Privacy Representatives
  • CM-9 Configuration Management Plan
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • PS-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SA-5 System Documentation
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 17 controls

  • AC-1 Policy and Procedures
  • AT-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CM-3(4) Security and Privacy Representatives
  • CM-9 Configuration Management Plan
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • PS-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SA-5 System Documentation
  • SR-1 Policy and Procedures (SR-1)
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

SOC 2 · 6 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

ISO 27002:2022 · 5 controls

  • 5.1 Policies for information security
  • 5.10 Acceptable use of information and other associated assets
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities

HIPAA Security Rule · 4 controls

C5 (Germany) · 3 controls

  • C5-OIS-01 Information Security Management System (ISMS)
  • C5-OIS-02 Information Security Policy
  • C5-SP-01 Documentation, communication and provision of policies and instructions

NIST SP 800-66 Rev 2 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-19 Information Security Policy Framework
  • CPS234-P19 Policy Direction to All Responsible Parties
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • P1-1.1.1 P1-1.1.1 Organisation-wide security policy exists and reaches everyone concerned
  • P1-1.1.3 P1-1.1.3 Policy changes communicated to the people affected

APPI · 1 control

  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data

CIS Controls v8 · 1 control

  • CIS-14.1 Establish and Maintain a Security Awareness Program

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 5.1 Policies for information security

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 156 it maps to, and the evidence behind each claim, over MCP and REST.