r12.5 Third-party service provider (TPSP) risk management and shared responsibility
Manage the risk associated with service providers that have access to account data or that can affect CDE security, including AWS, with a clear shared responsibility matrix.
AWS services
Requirement 12
Support Information Security with Organizational Policies and Programs
PCI sub-requirements covered
- 12.8 Risk to information assets associated with third-party service provider (TPSP) relationships is managed
How to implement on AWS
Maintain a list of TPSPs (including AWS) and monitor their PCI compliance status through the AOCs obtained in AWS Artifact. Document in writing which requirements each party manages (shared responsibility matrix). Review the TPSPs' compliance status at least annually.
Practical implementation
How this control is implemented in each reference architecture:
Maintain a TPSP list including AWS, monitor their PCI compliance via AOCs from AWS Artifact, and keep a written shared responsibility matrix; review annually.
Single-account, 3-tier →Manage the TPSP list and AWS AOCs once at the organization level (AWS Artifact organization agreements), and maintain a single shared responsibility matrix that applies to every account under the PCI OU.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine documentation to verify a list of all TPSPs is maintained with a description of the services provided (12.8.1.b).
- Examine documentation and interview personnel to verify each TPSP's PCI DSS compliance status is monitored at least every 12 months (12.8.4.b).
- Verify the entity maintains information about which PCI DSS requirements are managed by each TPSP, by the entity, or shared (12.8.5.a, 12.8.5.b).
Evidence in AWS
- TPSP list including AWS and their AOCs obtained via AWS Artifact.
- Shared responsibility matrix by PCI requirement.
- Evidence of annual review of the TPSPs' compliance status.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 12.8 — Records are maintained of third-party service providers (TPSPs) and the services provided, and their PCI DSS compliance status is monitored.
Learning resources
References
- PCI DSS v4.0.1 Requirement 12.8
PCI DSS Security Maturity Model