PCI DSS Security Maturity Model·AWS v1.0.0
Foundational Security Governance 👤 Customer

r12.5 Third-party service provider (TPSP) risk management and shared responsibility

Manage the risk associated with service providers that have access to account data or that can affect CDE security, including AWS, with a clear shared responsibility matrix.

Quick Wins
Foundational
Efficient
Optimized
Effort: Medium Impact: High Applies to CDE: Yes

AWS services

AWS Artifact

Requirement 12

Support Information Security with Organizational Policies and Programs

PCI sub-requirements covered

  • 12.8 Risk to information assets associated with third-party service provider (TPSP) relationships is managed

How to implement on AWS

Maintain a list of TPSPs (including AWS) and monitor their PCI compliance status through the AOCs obtained in AWS Artifact. Document in writing which requirements each party manages (shared responsibility matrix). Review the TPSPs' compliance status at least annually.

Practical implementation

How this control is implemented in each reference architecture:

Maintain a TPSP list including AWS, monitor their PCI compliance via AOCs from AWS Artifact, and keep a written shared responsibility matrix; review annually.

Single-account, 3-tier →

Manage the TPSP list and AWS AOCs once at the organization level (AWS Artifact organization agreements), and maintain a single shared responsibility matrix that applies to every account under the PCI OU.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineinterview

Testing procedures

  • Examine documentation to verify a list of all TPSPs is maintained with a description of the services provided (12.8.1.b).
  • Examine documentation and interview personnel to verify each TPSP's PCI DSS compliance status is monitored at least every 12 months (12.8.4.b).
  • Verify the entity maintains information about which PCI DSS requirements are managed by each TPSP, by the entity, or shared (12.8.5.a, 12.8.5.b).

Evidence in AWS

  • TPSP list including AWS and their AOCs obtained via AWS Artifact.
  • Shared responsibility matrix by PCI requirement.
  • Evidence of annual review of the TPSPs' compliance status.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 12.8 — Records are maintained of third-party service providers (TPSPs) and the services provided, and their PCI DSS compliance status is monitored.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 12.8