Auditen
Home / Frameworks / PCI DSS / Support information security with policies
PCI DSS · Req 12

Support information security with policies

Requirement 12 requires organizations to establish, document, and maintain a formal information security policy that defines the organization's approach to protecting cardholder data. This ensures that security is managed as a corporate mandate rather than an ad-hoc technical effort, with policies reviewed annually and communicated to all relevant personnel.

What it means

In practice, this requirement serves as the governance layer for the rest of PCI DSS. While other requirements focus on technical controls (like firewalls or encryption), Requirement 12 ensures there is a written "law of the land" that mandates those controls be implemented and maintained consistently across the organization.

The scope extends to all employees, contractors, and third parties who have access to the Cardholder Data Environment (CDE). It transforms security from a set of tasks into an organizational obligation, ensuring that leadership has formally approved the security strategy and that staff are aware of their responsibilities.

How to meet it

Evidence an auditor asks for

  • The current Information Security Policy document, including version history and approval dates.
  • Signed acknowledgments or digital logs proving that all personnel with CDE access have reviewed the policy.
  • Documented evidence of the most recent annual policy review (e.g., meeting minutes or a sign-off from management).
  • Organizational charts or job descriptions that explicitly map security responsibilities to specific roles.

Common pitfalls

  • "Shelfware": Maintaining a polished policy document that does not actually reflect how the organization operates in reality.
  • Generic Templates: Using an unedited industry template that references controls or departments that do not exist within the company.
  • Communication Gaps: Having a documented policy but failing to produce evidence (like signatures) that employees were actually notified of it.