Maintain PCI DSS Security Policy and Awareness Programme
What this control requires
Establish and maintain a comprehensive information security policy for all personnel. Conduct annual risk assessment. Implement security awareness programme covering all personnel annually. Define acceptable use of technology. Maintain an incident response plan tested at least annually. Review all third-party service providers annually for PCI DSS compliance status.
Other PCI DSS controls
PCI_DSS-CTRL-001 - Daily safeguarding reconciliationPCI_DSS-CTRL-002 - Critical ICT incident reportingPCI_DSS-CTRL-003 - GDPR breach notification workflowPCI_DSS-CTRL-004 - AML suspicious transaction monitoringPCI_DSS-CTRL-005 - Quarterly PCI vulnerability assessmentPCI_DSS-CTRL-006 - Outsourcing provider oversightPCI_DSS-CTRL-007 - DORA Register of Information maintenancePCI_DSS-CTRL-008 - CTIF suspicious activity escalationPCI_DSS-CTRL-009 - NIS2 cyber resilience testingPCI_DSS-CTRL-010 - Instant payment availability monitoringPCI-AUTH-001 - Implement Strong Access Control for Cardholder DataPCI-ENCRYPT-001 - Protect Stored Cardholder Data with Strong Cryptography