PCI DSS Security Maturity Model·AWS v1.0.0
Quick Wins Security Governance 👤 Customer

r12.2 Establish security and acceptable use policies

Establish, publish, and maintain a comprehensive information security policy and acceptable use policies for technologies, reviewed at least annually.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: Medium Applies to CDE: No

AWS services

AWS Organizations AWS Config

Requirement 12

Support Information Security with Organizational Policies and Programs

PCI sub-requirements covered

  • 12.1 A comprehensive information security policy is established, published, maintained, and disseminated
  • 12.2 Acceptable use policies for end-user technologies are defined and implemented

How to implement on AWS

Document the security and acceptable use policies and publish them to personnel. Codify the technical controls that back the policy as guardrails (SCPs, Config rules) so the policy intent is technically enforced. Review and update the policies at least every 12 months.

Practical implementation

How this control is implemented in each reference architecture:

Document and publish the security and acceptable-use policies, and back them with technical guardrails (Config rules, IAM policies) in the account so policy intent is enforced.

Single-account, 3-tier →

Codify policy intent as organization-wide guardrails: SCPs on the PCI OU plus Config conformance packs make the written policy technically enforceable across every account.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineinterview

Testing procedures

  • Examine the information security policy and interview personnel to verify it is established, published, maintained, and reviewed at least every 12 months (12.1.1, 12.1.2).
  • Examine the acceptable use policies for end-user technologies and interview personnel to verify they are documented and implemented per the requirement (12.2.1).

Evidence in AWS

  • Security and acceptable use policy documents with annual review history.
  • Technical guardrails (SCPs/Config rules) that reflect the policy.
  • Evidence of communicating the policies to personnel.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 12.1 — The strategic objectives and principles of information security are defined, adopted, and known to all personnel.
  • 12.2 — The use of end-user technologies is defined and managed to ensure authorized usage.

Learning resources

References

  • PCI DSS v4.0.1 Requirements 12.1, 12.2