PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.6.3: 12.6.3 Security awareness training on hire and annually with acknowledgment

Personnel must be trained in security awareness when hired, then again at least every 12 months; also, the program must use more than one way of communicating; and personnel must confirm (at least every 12 months) having read the security policy and procedures and grasped them. The guidance lists example methods (posters, letters, online or classroom sessions, team meetings, incentives) and notes acknowledgments can be written or electronic. Customized approach objective: personnel stay current on the threat landscape and their control responsibilities and can reach help and guidance when needed.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 76 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

CIS Controls v8 · 7 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.2 Train Workforce Members to Recognize Social Engineering Attacks
  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training

FedRAMP High · 6 controls

  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records

FedRAMP Moderate · 6 controls

  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records

ISO 27701:2019 · 6 controls

HIPAA Security Rule · 4 controls

ISO/IEC 42001:2023 · 4 controls

ISO 22301:2019 · 3 controls

  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

SOC 2 · 3 controls

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice

CMMC 2.0 · 2 controls

ISO 27002:2022 · 2 controls

  • 5.4 Management responsibilities
  • 6.3 Information security awareness, education and training

NIS2 Directive · 2 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-181 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • P1-1.1.5 P1-1.1.5 Personnel confirm they have read and understood the policy
  • P1-1.3.2 P1-1.3.2 Awareness training at set intervals, fitted to the role

APPI · 1 control

  • AUCDR-IS-6 Information security training and awareness program

C5 (Germany) · 1 control

  • C5-HR-03 Security training and awareness programme

ISO 27001:2022 · 1 control

  • 6.3 Information security awareness, education and training
  • 03.02.01 Literacy Training and Awareness

NIST SP 800-172 · 1 control

  • 3.2.1e Provide Awareness Training on Advanced Persistent Threat

UK Cyber Essentials · 1 control

  • CE-SC.7 Educate Users on Strong Passwords

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.