12.1The information security policy
You have an overall security policy, signed off by whoever runs the business, kept up to date, and your team knows what is in it.
There is an overall information security policy, approved by management, that sets the direction for protecting the organisation's information, is reviewed and kept current, is understood by the people it governs, and comes with security responsibilities assigned to named roles.
12.2Acceptable use of end-user technology
There are approved rules for how your team may use laptops, phones and memory sticks, and where card data is allowed to go.
There are approved rules for how staff may use the technology they are given - laptops, phones, removable storage, remote access - covering what may be done with each and where card data is and is not allowed to go.
12.3Identifying and managing risk to the card environment
You work out in writing what could go wrong for your card systems, including anywhere you chose the timing yourself, and act on what you find.
Risk to the card environment is identified and evaluated deliberately and in writing, including in the places the standard leaves to the organisation's own judgement: how often a control is performed, technology approaching the point where nobody supports it, and cryptography that is weakening with age.
12.4Managing the compliance programme
Somebody senior owns card security, and the day-to-day work gets checked through the year rather than only when an assessor turns up.
Overall responsibility for protecting card data sits with executive management, and the work of confirming that people are still doing what the procedures say is performed periodically by somebody other than the person doing it. Every specific requirement under this heading falls on service providers rather than on merchants.
12.5Documenting and confirming scope
You have written down which systems are in scope and how card data moves through your business, and you check that picture is still right.
There is an inventory of the components in scope and a record of how card data flows through the business, and the scope is confirmed as still accurate on a schedule. Everything else rests on this: a control applied to the wrong boundary protects nothing.
12.6Security awareness
Your team is trained on security when they join and again regularly, on material that gets updated as the threats change.
Security awareness runs as an ongoing programme rather than an induction: people are trained when they join and again at intervals, the material is refreshed as the threats change, and it covers what to do with a suspicious message and how card data is handled here.
12.7Screening personnel
You check the background of people before giving them access to card data, as far as the law where you are allows.
People who will be given access to the card environment are screened before they get it, to the extent the law where they work allows, so that trusting somebody with card data is a decision rather than a default.
12.8Managing third-party service providers
You have a list of the outside companies that touch your card payments, a written split of who does what on security, and you check on them.
The organisation keeps a list of the providers that hold card data for it or could affect the security of it, checks their standing before engaging them, agrees in writing which security duties belong to whom, and monitors that those duties are still being met.
12.9Support a provider owes its customers
If you handle card payments for other businesses, you owe them a written acknowledgement and the evidence they need for their own checks.
A provider handling card data on behalf of other businesses acknowledges in writing that it is responsible for the data it holds, and gives those customers the information they need to assess their own position. This falls on service providers rather than on merchants.
12.10Responding to a suspected incident
You have a plan for a suspected card data breach that says who does what and who you must tell, and you have tested it.
There is an incident response plan that can be acted on immediately: who does what, how the acquirer and the payment brands get told, how containment and recovery proceed. It is tested and revised, and the people named in it are available and trained to play their part.