Skip to contentSkip to content
Maintain an Information Security Policy
12

Support Information Security with Organisational Policies and Programmes

A comprehensive information security policy sets the tone for the entire organisation and communicates security expectations to all personnel. This requirement covers policy management, risk assessment, security awareness training, incident response, and third-party service provider management.

Control Intent

Establish, maintain, and communicate an information security programme supported by policies, training, risk assessment, and incident response procedures that protect cardholder data throughout the organisation and its third-party relationships.

Common Failures

  • Information security policy not reviewed or updated annually, becoming outdated and not reflecting current environment
  • Risk assessment performed as a checkbox exercise without substantive analysis of threats to cardholder data
  • Security awareness training not targeted to phishing and social engineering threats or not updated for emerging attack methods
  • Incident response plan not tested annually through tabletop exercises or simulations
  • Third-party service providers not monitored for PCI DSS compliance status, creating unmanaged risk