PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.4.2: 12.4.2 Quarterly reviews that personnel follow security procedures

Service providers only: at least every three months, reviews must confirm that personnel carry out their tasks in keeping with every security policy and operational procedure. The reviews must be done by people other than those responsible for the task, and they cover at least: daily log reviews; configuration reviews of network security controls; applying configuration standards when new systems are built; handling of security alerts; and change-management processes. The guidance explains the aim is to confirm activities happen, not to redo them. Applicability: applies only when the assessed entity is a service provider. Customized approach objective: periodic manual inspection of records confirms that key PCI DSS controls operate effectively.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 60 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

ISO 27002:2022 · 5 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.37 Documented operating procedures
  • 5.4 Management responsibilities
  • 6.3 Information security awareness, education and training
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

SOC 2 · 5 controls

  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

CMMC 2.0 · 4 controls

ISO 22301:2019 · 3 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.3 Management review

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities

ISO/IEC 42001:2023 · 3 controls

  • 8.1 Operational planning and control
  • 9.2 Internal audit
  • 9.3 Management review

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls

C5 (Germany) · 2 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

FedRAMP High · 2 controls

  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring

FedRAMP Moderate · 2 controls

  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring

NIS2 Directive · 2 controls

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 800-171 Rev 3 · 2 controls

CIS Controls v8 · 1 control

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 6.15.2 Information security reviews

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 53A-F Ongoing Assessment and Automation
  • P2-2.3.1 P2-2.3.1 Periodic checks that staff follow security policies

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.4.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.