PCI DSS 4.0 12.3.2: 12.3.2 Targeted risk analysis for each customized-approach requirement
For every requirement the entity meets through the customized approach, a targeted risk analysis must be carried out that includes: documented evidence covering each element set out in Appendix D (Customized Approach), at minimum a controls matrix and a risk analysis; sign-off of that evidence by senior management; and redoing the analysis on a cycle of at least every 12 months. Applicability: applies only to entities that use a Customized Approach. Customized approach objective: this requirement forms part of the customized approach itself and must be satisfied by anyone using that approach.
This control maps to 55 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 12.3.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.