PCI DSS 12.1.4: Responsibility for information security is formally assigned to a Chief Information Security
PCI DSS v4.0.1 control 12.1.4: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.1.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.1
Responsibility for information security is formally assigned to a Chief Information Security Officer or other information security knowledgeable member of executive management. .
Summary
One named executive is formally accountable for information security.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.1.4 | Examine the information security policy to verify that information security is formally assigned to a Chief Information Security Officer or other information security-knowledgeable member of executive management. |
The shortest control in Requirement 12 and one of the few that names a person rather than a process. Responsibility is formally assigned to a Chief Information Security Officer or other information security knowledgeable member of executive management, and both halves of that phrase matter. It must be someone at executive level, so a security manager reporting three layers down does not satisfy it. And it must be someone knowledgeable about information security, which is what stops the assignment defaulting to whichever executive had capacity. The procedure examines the information security policy for the assignment, so this lives in the policy rather than in a job description or an org chart.
What to prepare
- The information security policy, showing the assignment by role.
- Who currently holds it, and their position in the executive structure.
- Evidence of their information security knowledge if the title is not CISO.
- How the assignment is maintained when the holder changes.
How to implement it
1. Put it in the policy, since that is where it is examined. An assignment that exists only in an org chart is not where the procedure looks.
2. Assign to a role and keep the holder current. A named individual who has left is a failed control and an easy one to leave stale.
3. Be able to evidence the knowledge element where the holder is not a security professional by title, which is common in smaller organisations and is acceptable if defensible.
4. Do not split it. Overall accountability assigned to a committee is not a member of executive management.
Where this commonly fails
- Assignment held by a manager below executive level.
- The policy naming someone who has left the organisation.
- Accountability spread across a committee with no individual holder.
- The assignment recorded everywhere except the information security policy.
Related controls
Others in section 12.1:
| Control | What it requires |
|---|---|
| 12.1.1 | An overall information security policy… |
| 12.1.2 | The information security policy… |
| 12.1.3 | The security policy clearly defines information security roles and responsibilities for all… |
← 12.1.3 · All controls · 12.2.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.