CyberTRIZPEDIA

Information Security Programme and Awareness

Control
PCI-R12-001
Regulation
PCI DSS
Category
governance
Priority
high
Frequency
annually
Type
governance

What this control requires

Maintain a comprehensive information security policy reviewed annually. Implement security awareness training for all personnel annually. Conduct annual risk assessment. Screen all personnel before access to CDE. Manage service providers with PCI DSS compliance verification. Maintain incident response plan tested annually.

Other PCI DSS controls