PCI DSS 12.3.2: A targeted risk analysis is performed for each PCI DSS requirement that the entity meets
PCI DSS v4.0.1 control 12.3.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.3.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.3
A targeted risk analysis is performed for each PCI DSS requirement that the entity meets with the customized approach, to include:
- Documented evidence detailing each element specified in Appendix D: Customized Approach (including, at a minimum, a controls matrix and risk analysis).
- Approval of documented evidence by senior management.
- Performance of the targeted analysis of risk at least once every 12 months.
Summary
If you use the customized approach for a requirement, you have to do a targeted risk analysis for it, get senior management to approve it, and redo it yearly.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.3.2 | Examine the documented targeted risk-analysis for each PCI DSS requirement that the entity meets with the customized approach to verify that documentation for each requirement exists and is in accordance with all elements specified in this requirement. |
This applies only where the customized approach is used, and reading it is a good way to understand what that approach actually costs. Three elements: documented evidence detailing each element specified in Appendix D, which at a minimum means a controls matrix and a risk analysis; approval by senior management; and performance at least once every 12 months. That is per requirement, not once for the entity, so an entity meeting five requirements by the customized approach maintains five of these and refreshes all five annually. The customized approach is a genuine and useful route for a control you meet in a way the defined approach does not describe, and this control is where its ongoing cost sits. Note the distinction from the other targeted risk analyses in the standard: those set a frequency, this one justifies a whole alternative implementation.
What to prepare
- The list of requirements met by the customized approach.
- For each: the controls matrix and risk analysis per Appendix D.
- Senior management approval for each, dated.
- Evidence of the annual refresh.
How to implement it
1. Count the requirements first. The cost is per requirement and annual, and it is worth knowing the total before choosing this route for one more.
2. Follow Appendix D rather than writing free-form. The elements are specified there and the procedure examines against them.
3. Get senior management approval as a real decision. They are approving that an alternative implementation meets the objective, which is a risk acceptance and not a formality.
4. Diarise the annual refresh per requirement. Each has its own cycle and one lapsing fails this control for that requirement.
Where this commonly fails
- One analysis covering several customized-approach requirements, when it is required per requirement.
- Documentation that does not follow Appendix D, so elements are missing.
- Approval by a manager rather than senior management.
- The first year done thoroughly and the annual refresh missed.
Related controls
Others in section 12.3:
| Control | What it requires |
|---|---|
| 12.3.1 | For each PCI DSS requirement that specifies completion of a targeted risk analysis… |
| 12.3.3 | Cryptographic cipher suites and protocols in use are documented and reviewed at least once… |
| 12.3.4 | Hardware and software technologies in use are reviewed at least once every 12 months… |
← 12.3.1 · All controls · 12.3.3 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.