PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.6.3: Security awareness training delivered

Personnel receive security awareness training upon hire and at least once every 12 months, covering threats and vulnerabilities including phishing, social engineering, and acceptable use.

What else in your programme already covers this

This control maps to 91 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

  • NIST800-AT-1 Policy and procedures for awareness and training
  • NIST800-AT-2 Literacy training and awareness
  • NIST800-AT-3 Role-based training
  • NIST800-AT-4 Training records
  • NIST800-PM-13 Security and Privacy Workforce. Establish a security and privacy workforce development and improvement program
  • NIST800-PM-14 Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be
  • NIST800-PS-1 Policy and procedures for personnel security
  • SP800-53-AT Awareness and Training Family

CIS Controls v8 · 7 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.2 Train Workforce Members to Recognize Social Engineering Attacks
  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training

FedRAMP High · 6 controls

  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records

FedRAMP Moderate · 6 controls

  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records

ISO 27701:2019 · 6 controls

  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-3 Role-Based Training
  • AT-4 Training Records

HIPAA Security Rule · 4 controls

ISO/IEC 42001:2023 · 4 controls

ISO 22301:2019 · 3 controls

  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

SOC 2 · 3 controls

  • SOC2-CC1.4 COSO principle 4: Demonstrates commitment to attract and retain competent individuals
  • SOC2-CC2.2 COSO principle 14: Internally communicates information including objectives and responsibilities
  • SOC2-CC5.3 COSO principle 12: Deploys control activities through policies and procedures
  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice

CMMC 2.0 · 2 controls

ISO 27002:2022 · 2 controls

  • 5.4 Management responsibilities
  • 6.3 Information security awareness, education and training

NIS2 Directive · 2 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-181 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

APPI · 1 control

  • AUCDR-IS-6 Information security training and awareness program

C5 (Germany) · 1 control

  • C5-HR-03 Security training and awareness programme

ISO 27001:2022 · 1 control

  • 6.3 Information security awareness, education and training
  • 03.02.01 Literacy Training and Awareness

NIST SP 800-172 · 1 control

  • 3.2.1e Provide Awareness Training on Advanced Persistent Threat

UK Cyber Essentials · 1 control

  • CE-SC.7 Educate Users on Strong Passwords

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 249 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.