r12.3 Formalize risk management (targeted risk analysis)
Perform the targeted risk analyses that v4.0.1 requires to support the frequency of certain controls and the organization's risk management.
AWS services
Requirement 12
Support Information Security with Organizational Policies and Programs
PCI sub-requirements covered
- 12.3 Risks to the CDE are formally identified, evaluated, and managed
How to implement on AWS
Establish a targeted risk analysis process for the requirements that allow it. Support risk identification with the posture observed in Security Hub and AWS Config. Document the analyses, their periodicity, and the resulting decisions. Review at least every 12 months.
Practical implementation
How this control is implemented in each reference architecture:
Establish a targeted risk analysis process for the requirements that allow it, supported by the posture you observe in Security Hub and Config in the account.
Single-account, 3-tier →Feed the targeted risk analyses with organization-wide posture from the Security Hub/Config aggregators, so risk decisions reflect the state of all CDE accounts, not just one.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine documented policies to verify a process is defined for performing a targeted risk analysis for each requirement that allows it, covering all required elements (12.3.1).
- Examine documentation for cryptographic suites/protocols and hardware/software technologies in use and interview personnel to verify periodic review (12.3.3, 12.3.4).
Evidence in AWS
- Targeted risk analysis documents with periodicity and decisions.
- Referenced risk-posture inputs from Security Hub/Config.
- Evidence of review at least every 12 months.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 12.3 — Up-to-date knowledge and assessment of risks to the CDE are maintained.
Learning resources
References
- PCI DSS v4.0.1 Requirement 12.3
PCI DSS Security Maturity Model