PCI DSS Security Maturity Model·AWS v1.0.0
Foundational Security Governance 👤 Customer

r12.3 Formalize risk management (targeted risk analysis)

Perform the targeted risk analyses that v4.0.1 requires to support the frequency of certain controls and the organization's risk management.

Quick Wins
Foundational
Efficient
Optimized
Effort: Medium Impact: Medium Applies to CDE: No

AWS services

AWS Security Hub AWS Config

Requirement 12

Support Information Security with Organizational Policies and Programs

PCI sub-requirements covered

  • 12.3 Risks to the CDE are formally identified, evaluated, and managed

How to implement on AWS

Establish a targeted risk analysis process for the requirements that allow it. Support risk identification with the posture observed in Security Hub and AWS Config. Document the analyses, their periodicity, and the resulting decisions. Review at least every 12 months.

Practical implementation

How this control is implemented in each reference architecture:

Establish a targeted risk analysis process for the requirements that allow it, supported by the posture you observe in Security Hub and Config in the account.

Single-account, 3-tier →

Feed the targeted risk analyses with organization-wide posture from the Security Hub/Config aggregators, so risk decisions reflect the state of all CDE accounts, not just one.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examine

Testing procedures

  • Examine documented policies to verify a process is defined for performing a targeted risk analysis for each requirement that allows it, covering all required elements (12.3.1).
  • Examine documentation for cryptographic suites/protocols and hardware/software technologies in use and interview personnel to verify periodic review (12.3.3, 12.3.4).

Evidence in AWS

  • Targeted risk analysis documents with periodicity and decisions.
  • Referenced risk-posture inputs from Security Hub/Config.
  • Evidence of review at least every 12 months.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 12.3 — Up-to-date knowledge and assessment of risks to the CDE are maintained.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 12.3