PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.4.2.1: 12.4.2.1 Documentation of quarterly operational reviews

Service providers only: the reviews carried out under Requirement 12.4.2 must be recorded, and the records must include: the review results; the remediation actions documented for any task found not to have been done; and review and sign-off of the results by the people who own the PCI DSS compliance program. Applicability: applies only when the assessed entity is a service provider. Customized approach objective: management evaluates findings from operational effectiveness reviews and suitable remediation is carried out.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 44 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

ISO 22301:2019 · 4 controls

  • 10.2 Continual improvement
  • 7.5.3 Control of documented information
  • 9.2.2 Audit programme(s)
  • 9.3.2 Management review input

ISO 27001:2022 · 4 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities

ISO 27002:2022 · 4 controls

  • 5.2 Information security roles and responsibilities
  • 5.22 Monitoring, review and change management of supplier services
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

ISO/IEC 42001:2023 · 3 controls

  • 10.2 Nonconformity and corrective action
  • 7.5.3 Control of documented information
  • 9.3 Management review

HIPAA Security Rule · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

NIST SP 800-66 Rev 2 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)

APRA CPS 234 · 1 control

  • CPS234-28 Escalation of Unremediated Testing Deficiencies

C5 (Germany) · 1 control

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

CMMC 2.0 · 1 control

FedRAMP High · 1 control

  • CA-7 Continuous Monitoring

FedRAMP Moderate · 1 control

  • CA-7 Continuous Monitoring

ISO 27701:2019 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.4.2.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 44 it maps to, and the evidence behind each claim, over MCP and REST.