PCI DSS Security Maturity Model·AWS v1.0.0
Foundational Security Governance 👤 Customer

r12.4 Security awareness program

Implement a formal security awareness program so that personnel understand their role in protecting account data, with updates as threats emerge.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: Medium Applies to CDE: No

AWS services

AWS Training and Certification

Requirement 12

Support Information Security with Organizational Policies and Programs

PCI sub-requirements covered

  • 12.6 Security awareness education is an ongoing activity

How to implement on AWS

Establish training upon hire and at least annually, including phishing and social engineering. Maintain attendance/completion records. Update the content as threats emerge. Reinforce with the technical anti-phishing protection of Requirement 5.4.

Practical implementation

How this control is implemented in each reference architecture:

Run onboarding and annual security awareness training (including phishing), keep completion records, and reinforce it with the technical anti-phishing controls of Requirement 5.4.

Single-account, 3-tier →

Awareness is an organizational (not per-account) control; run one program for all personnel, tie technical anti-phishing guardrails from the shared accounts to it, and keep central completion records.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineinterview

Testing procedures

  • Examine the security awareness program to verify it educates personnel on the security policy and their role in protecting cardholder data (12.6.1).
  • Examine program records to verify personnel attend awareness training upon hire and at least every 12 months, and acknowledge the policy annually (12.6.3.a, 12.6.3.d).

Evidence in AWS

  • Awareness program materials and their schedule.
  • Training completion records for personnel.
  • Content updates in response to new threats.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 12.6 — Personnel are knowledgeable about the threat landscape and their responsibility for the operation of relevant security controls.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 12.6