PCI DSS 4.0 12.1.1: 12.1.1 Overall information security policy established and disseminated
The organisation must have one overarching information security policy that is formally set up, made available in published form, kept under maintenance, and distributed to every relevant member of personnel and to vendors and business partners who are relevant. The guidance defines 'relevant' as anyone whose role, internal or as an outside provider of services or functions, touches some or all of the topics the policy addresses. The guidance explains that this top-level policy governs the more specific technical and discipline policies beneath it. Objective under the customized approach: the strategic aims and principles of information security are set out, formally adopted, and understood by everyone who works for the entity.
This control maps to 156 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 12.1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.