r12.4 Security awareness program
Implement a formal security awareness program so that personnel understand their role in protecting account data, with updates as threats emerge.
AWS services
Requirement 12
Support Information Security with Organizational Policies and Programs
PCI sub-requirements covered
- 12.6 Security awareness education is an ongoing activity
How to implement on AWS
Establish training upon hire and at least annually, including phishing and social engineering. Maintain attendance/completion records. Update the content as threats emerge. Reinforce with the technical anti-phishing protection of Requirement 5.4.
Practical implementation
How this control is implemented in each reference architecture:
Run onboarding and annual security awareness training (including phishing), keep completion records, and reinforce it with the technical anti-phishing controls of Requirement 5.4.
Single-account, 3-tier →Awareness is an organizational (not per-account) control; run one program for all personnel, tie technical anti-phishing guardrails from the shared accounts to it, and keep central completion records.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine the security awareness program to verify it educates personnel on the security policy and their role in protecting cardholder data (12.6.1).
- Examine program records to verify personnel attend awareness training upon hire and at least every 12 months, and acknowledge the policy annually (12.6.3.a, 12.6.3.d).
Evidence in AWS
- Awareness program materials and their schedule.
- Training completion records for personnel.
- Content updates in response to new threats.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 12.6 — Personnel are knowledgeable about the threat landscape and their responsibility for the operation of relevant security controls.
Learning resources
- AWS Skill Builder (doc)
References
- PCI DSS v4.0.1 Requirement 12.6
PCI DSS Security Maturity Model