PCI DSS 1.1.2: Roles and responsibilities for performing activities in Requirement 1 are documented, assigned
PCI DSS v4.0.1 control 1.1.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 1.1.
Requirement 1: Install and Maintain Network Security Controls › Section 1.1
Roles and responsibilities for performing activities in Requirement 1 are documented, assigned, and understood.
Summary
Someone is named for each Requirement 1 activity, including the two nobody usually claims.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 1.1.2.a | Examine documentation to verify that descriptions of roles and responsibilities for performing activities in Requirement 1 are documented and assigned. |
| 1.1.2.b | Interview personnel responsible for performing activities in Requirement 1 to verify that roles and responsibilities are assigned as documented and are understood. |
Requirement 1 splits its activities across teams that do not naturally overlap, and two of them routinely have no owner at all. The first is the data-flow diagram in 1.2.4: keeping it accurate requires knowing the business process rather than the network, so the network team cannot own it and the business does not know it exists. The second is the six-monthly NSC configuration review in 1.2.7, a periodic task with no natural home that simply does not happen unless assigned. Meanwhile rule changes are made by network engineering and by application teams provisioning cloud security groups, so the population performing the most frequent activity is wider than the matrix usually admits. 1.1.2.b interviews the people named.
What to prepare
- A responsibility matrix by role for each Requirement 1 activity.
- The named owner of each of the two diagrams, which are different jobs.
- The named owner of the six-monthly review.
- Everyone who can change an NSC configuration, including in cloud consoles.
How to implement it
1. Assign the two diagrams separately. The network diagram belongs with whoever knows the topology; the data-flow diagram belongs with whoever knows where account data goes, and they are rarely the same person.
2. Give the six-monthly review a named owner and a date. It is the activity most likely to be discovered undone at assessment.
3. Count the cloud changers. Application teams altering security groups are performing a Requirement 1 activity, and an unassigned population is an unreviewed one.
4. Assign by role with a current role-to-person mapping. Network responsibilities outlive individuals and reorganisations reassign them silently.
Where this commonly fails
- The data-flow diagram unowned, so it ages until someone needs it for scoping.
- The six-monthly review unassigned and therefore unperformed.
- Only network engineering named, while application teams change rules daily.
- A matrix accurate for the data centre and silent about cloud.
Related controls
Others in section 1.1:
| Control | What it requires |
|---|---|
| 1.1.1 | All security policies and operational procedures that are identified in Requirement 1… |
← 1.1.1 · All controls · 1.2.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.