CyberTRIZPEDIA

Maintain PCI DSS Security Policy and Awareness Programme

Control
PCI-POLICY-001
Regulation
PCI DSS
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Establish and maintain a comprehensive information security policy for all personnel. Conduct annual risk assessment. Implement security awareness programme covering all personnel annually. Define acceptable use of technology. Maintain an incident response plan tested at least annually. Review all third-party service providers annually for PCI DSS compliance status.

Other PCI DSS controls