PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.1.2: 12.1.2 Security policy reviewed annually and updated as needed

The overall information security policy must be reviewed on a cycle no longer than 12 months, plus revised whenever needed so that it keeps pace with shifts in business objectives or in the risks facing the environment. The guidance explains that, as threats and defences evolve quickly, an unrevised policy may fail to address new protective measures. Customized approach objective: the policy keeps mirroring the entity's strategic security aims and principles over time.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 128 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 20 controls

  • AC-1 Policy and Procedures
  • AT-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CM-9 Configuration Management Plan
  • CP-1 Policy and Procedures
  • IA-1 Policy and Procedures
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • PS-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SC-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)
  • SR-2 Supply Chain Risk Management Plan (SR-2)

FedRAMP Moderate · 20 controls

  • AC-1 Policy and Procedures
  • AT-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CM-9 Configuration Management Plan
  • CP-1 Policy and Procedures
  • IA-1 Policy and Procedures
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • PS-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SC-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)
  • SR-2 Supply Chain Risk Management Plan (SR-2)

ISO 22301:2019 · 14 controls

  • 10.1 Nonconformity and corrective action
  • 4.2.2 Legal and regulatory requirements
  • 4.4 Business continuity management system
  • 5.1 Leadership and commitment
  • 5.2.1 Establishing the business continuity policy
  • 6.1.1 Determining risks and opportunities
  • 6.3 Planning changes to the business continuity management system
  • 7.5 Documented information
  • 7.5.1 General
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • 9.2.1 General
  • 9.3 Management review
  • 9.3.1 General

ISO 27701:2019 · 13 controls

  • 5.1 General
  • 5.2 Context of the organization
  • 5.2.4 Information security management system
  • 5.3 Leadership
  • 5.3.1 Leadership and commitment
  • 5.3.2 Policy
  • 5.4 Planning
  • 5.8.2 Continual improvement
  • 6.2 Information security policies
  • 6.2.1 Management direction for information security
  • 6.3 Organization of information security
  • 6.9.1 Operational procedures and responsibilities
  • 8.1 General

ISO/IEC 42001:2023 · 13 controls

  • 10.1 Continual improvement
  • 4.4 AI management system
  • 5.1 Leadership and commitment
  • 5.2 AI policy
  • 6.1 Actions to address risks and opportunities
  • 6.2 AI objectives and planning to achieve them
  • 7.5.2 Creating and updating documented information
  • 9.3 Management review
  • A.2 Policies related to AI
  • A.2.2 AI policy
  • A.2.3 Alignment with other organizational policies
  • A.2.4 Review of the AI policy
  • A.3 Internal organization

NIST SP 800-53 Rev 5 · 12 controls

  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

SOC 2 · 6 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

HIPAA Security Rule · 4 controls

ISO 27002:2022 · 4 controls

  • 5.1 Policies for information security
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities

APRA CPS 234 · 2 controls

  • CPS234-19 Information Security Policy Framework
  • CPS234-P17 Active Maintenance of Capability Against Change

C5 (Germany) · 2 controls

  • C5-OIS-02 Information Security Policy
  • C5-SP-02 Review and Approval of Policies and Instructions

NIST SP 800-66 Rev 2 · 2 controls

  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data

CIS Controls v8 · 1 control

  • CIS-3.1 Establish and Maintain a Data Management Process

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 5.1 Policies for information security

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security
  • P1-1.1.2 P1-1.1.2 Policy revised when business aims or risks change

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.1.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 128 it maps to, and the evidence behind each claim, over MCP and REST.