PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.2.1: 12.2.1 Rules for acceptable use of end-user technology

Acceptable use policies covering end-user technologies must be written down and put into practice, and must contain: explicit approval of use by authorised parties; the permitted uses of each technology; and an inventory of company-approved hardware and software products for staff use. Applicability: examples of technologies expected to be covered include remote access and wireless, laptops, tablets, mobile phones, removable electronic media, email and Internet usage, though the list is not exhaustive. Objective under the customized approach: use of end-user technology is defined and controlled so that only authorised usage happens.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 57 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

CIS Controls v8 · 5 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-5.6 Centralize Account Management

ISO 27002:2022 · 5 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.9 Inventory of information and other associated assets
  • 6.7 Remote working
  • 8.1 User endpoint devices
  • 8.5 Secure authentication

ISO 27701:2019 · 5 controls

  • 6.2.1 Management direction for information security
  • 6.3.2 Mobile devices and teleworking
  • 6.4.2 During employment
  • 6.6.2 User access management
  • 6.6.3 User responsibilities
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice
  • ANSSI-HYG-15 Protect Against Threats Related to Removable Media
  • ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices
  • ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals

FedRAMP High · 4 controls

  • CM-10 Software Usage Restrictions
  • MP-7 Media Use
  • PL-4 Rules of Behavior
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))

FedRAMP Moderate · 4 controls

  • CM-10 Software Usage Restrictions
  • MP-7 Media Use
  • PL-4 Rules of Behavior
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))

ISO 27001:2022 · 4 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.9 Inventory of information and other associated assets
  • 6.7 Remote working
  • 8.1 User end point devices

CMMC 2.0 · 3 controls

  • CCM-HRS-02 Acceptable Use of Technology Policy and Procedures
  • CCM-UEM-01 Endpoint Devices Policy and Procedures
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

NIST SP 800-171 Rev 3 · 2 controls

  • P2-4.3.2 P2-4.3.2 Remote access controlled and documented
  • P2-4.3.3 P2-4.3.3 Rules for personally owned devices used remotely

SOC 2 · 2 controls

  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

APPI · 1 control

  • ASD37-13 Control removable storage media (Very Good)

C5 (Germany) · 1 control

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy

HIPAA Security Rule · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.2.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.