PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.5.2: 12.5.2 Annual and change-driven scope confirmation

The entity must document its PCI DSS scope and confirm it at least once every 12 months, plus whenever the in-scope environment changes significantly. The scoping validation must at minimum: identify all data flows across payment stages (for instance authorisation, capture, settlement, chargebacks, refunds) and every acceptance channel (for instance card-present, card-not-present, e-commerce); update all data-flow diagrams under Requirement 1.2.4; identify every place where account data is held, processed or sent, including places outside the current CDE, applications handling CHD, data transmitted across networks and systems, and backups of files; identify all components in, connected to, or able to affect the CDE; identify all segmentation controls and the environments segmented from the CDE, with justification for out-of-scope environments; identify all third-party connections with CDE access; and confirm all these items are included in scope. Applicability: this is the entity's own confirmation and is separate from, and not replaced by, the assessor's scoping check during the annual assessment. Objective under the customized approach: scope is checked periodically and after significant change through thorough analysis and suitable technical measures.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 70 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 7 controls

  • CA-3 Information Exchange
  • CM-12 Information Location (CM-12)
  • CM-8 System Component Inventory
  • PL-2 System Security and Privacy Plans
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SC-7(4) External Telecommunications Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)

FedRAMP Moderate · 7 controls

  • CA-3 Information Exchange
  • CM-12 Information Location (CM-12)
  • CM-8 System Component Inventory
  • PL-2 System Security and Privacy Plans
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SC-7(4) External Telecommunications Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)

NIST SP 800-53 Rev 5 · 6 controls

  • NIST800-PL-2 PL-2 System Security and Privacy Plans
  • NIST800-PM-10 PM-10 Authorization Process
  • NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information
  • NIST800-RA-3 RA-3 Risk Assessment
  • SP800-53-PL Planning Family
  • SP800-53-PM Program Management Family

ISO 22301:2019 · 4 controls

  • 4.2.2 Legal and regulatory requirements
  • 4.3 Determining the scope of the business continuity management system
  • 4.3.2 Scope of the business continuity management system
  • 9.3.2 Management review input

ISO 27001:2022 · 4 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.35 Independent review of information security
  • 5.37 Documented operating procedures

ISO 27701:2019 · 4 controls

  • 5.2 Context of the organization
  • 5.2.3 Determining the scope of the information security management system
  • 6.5.2 Information classification
  • 8.2 Conditions for collection and processing

ISO/IEC 42001:2023 · 4 controls

  • 4.3 Determining the scope of the AI management system
  • 7.5.3 Control of documented information
  • 9.2 Internal audit
  • 9.3 Management review

C5 (Germany) · 3 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-OIS-03 Interfaces and Dependencies
  • C5-PSS-12 Locations of Data Processing and Storage

ISO 27002:2022 · 3 controls

  • 5.37 Documented operating procedures
  • 5.9 Inventory of information and other associated assets
  • 8.22 Segregation of networks
  • P2-1.1.1 P2-1.1.1 In-scope networks and components identified
  • P2-1.1.2 P2-1.1.2 Out-of-scope networks justified with their segmentation
  • P2-1.1.3 P2-1.1.3 Connected entities with 3DE access identified
  • ASBv3-AM-1 Track asset inventory and their risks
  • ASBv3-DP-1 Discover, classify, and label sensitive data
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained

NIST SP 800-171 Rev 3 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)

UK Cyber Essentials · 2 controls

  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram

APRA CPS 234 · 1 control

  • CPS234-20 Information Asset Classification
  • SEC01-BP03 Identify and validate control objectives
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment

CIS Controls v8 · 1 control

  • CIS-3.1 Establish and Maintain a Data Management Process

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

NIS2 Directive · 1 control

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.5.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 70 it maps to, and the evidence behind each claim, over MCP and REST.