PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.8.4: 12.8.4 Annual monitoring of TPSP compliance status

The entity must run a program that checks, at least every 12 months, where each TPSP stands on PCI DSS compliance. Applicability: where a TPSP meets PCI DSS requirements on the entity's behalf (a firewall service, for example), the entity must work with it to ensure those requirements are met; if the TPSP falls short, those requirements also count as not in place for the entity. Customized approach objective: each TPSP's compliance standing gets checked periodically.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 71 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

  • NIST800-AC-20 AC-20 Use of External Systems
  • NIST800-CA-7 CA-7 Continuous Monitoring
  • NIST800-PS-7 PS-7 External Personnel Security
  • NIST800-SA-9 SA-9 External System Services
  • NIST800-SR-6 SR-6 Supplier Assessments and Reviews
  • SP800-53-SA System and Services Acquisition Family
  • SP800-53-SR Supply Chain Risk Management Family

FedRAMP High · 6 controls

  • AC-20 Use of External Systems
  • CA-3 Information Exchange
  • SA-9 External System Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 6 controls

  • AC-20 Use of External Systems
  • CA-3 Information Exchange
  • SA-9 External System Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

APRA CPS 234 · 4 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-27 Internal Audit Assessment of Third Party Control Assurance
  • CPS234-P22 Evaluation of Third Party Control Design
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing

CIS Controls v8 · 4 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.3 Classify Service Providers
  • CIS-15.5 Assess Service Providers
  • CIS-15.6 Monitor Service Providers

HIPAA Security Rule · 4 controls

ISO 27701:2019 · 4 controls

  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.12.2 Supplier service delivery management
  • 6.15.1 Compliance with legal and contractual requirements

NIST SP 800-66 Rev 2 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties

ISO 27001:2022 · 2 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services

ISO 27002:2022 · 2 controls

  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • 03.16.03 External System Services
  • 03.17.03 Supply Chain Requirements and Processes
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management

APPI · 1 control

  • ASBv3-PA-8 Determine access process for cloud provider support

C5 (Germany) · 1 control

  • C5-SSO-04 Monitoring of compliance with requirements
  • CFTC-SS-31 Testing Covers Outsourced Resources and Tester Independence from Providers

CMMC 2.0 · 1 control

ISO 22301:2019 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO/IEC 42001:2023 · 1 control

NIST SP 800-172 · 1 control

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • P2-2.4.4 P2-2.4.4 Third parties' agreed responsibilities verified periodically

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.8.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 71 it maps to, and the evidence behind each claim, over MCP and REST.