r12.2 Establish security and acceptable use policies
Establish, publish, and maintain a comprehensive information security policy and acceptable use policies for technologies, reviewed at least annually.
AWS services
Requirement 12
Support Information Security with Organizational Policies and Programs
PCI sub-requirements covered
- 12.1 A comprehensive information security policy is established, published, maintained, and disseminated
- 12.2 Acceptable use policies for end-user technologies are defined and implemented
How to implement on AWS
Document the security and acceptable use policies and publish them to personnel. Codify the technical controls that back the policy as guardrails (SCPs, Config rules) so the policy intent is technically enforced. Review and update the policies at least every 12 months.
Practical implementation
How this control is implemented in each reference architecture:
Document and publish the security and acceptable-use policies, and back them with technical guardrails (Config rules, IAM policies) in the account so policy intent is enforced.
Single-account, 3-tier →Codify policy intent as organization-wide guardrails: SCPs on the PCI OU plus Config conformance packs make the written policy technically enforceable across every account.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine the information security policy and interview personnel to verify it is established, published, maintained, and reviewed at least every 12 months (12.1.1, 12.1.2).
- Examine the acceptable use policies for end-user technologies and interview personnel to verify they are documented and implemented per the requirement (12.2.1).
Evidence in AWS
- Security and acceptable use policy documents with annual review history.
- Technical guardrails (SCPs/Config rules) that reflect the policy.
- Evidence of communicating the policies to personnel.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 12.1 — The strategic objectives and principles of information security are defined, adopted, and known to all personnel.
- 12.2 — The use of end-user technologies is defined and managed to ensure authorized usage.
Learning resources
References
- PCI DSS v4.0.1 Requirements 12.1, 12.2
PCI DSS Security Maturity Model