PCI DSS 12.4.2 (service providers): Reviews are performed at least once every three months to confirm that personnel are performing

PCI DSS v4.0.1 control 12.4.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 12.4.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.4

Additional requirement for service providers only: Reviews are performed at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures. Reviews are performed by personnel other than those responsible for performing the given task and include, but are not limited to, the following tasks:

  • Daily log reviews.
  • Configuration reviews for network security controls.
  • Applying configuration standards to new systems.
  • Responding to security alerts.
  • Change-management processes.

Summary

Service providers: every three months, someone independent checks that people are actually doing the security tasks they are supposed to.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.4.2.a Additional testing procedure for service provider assessments only: Examine policies and procedures to verify that processes are defined for conducting reviews to confirm that personnel are performing their tasks in accordance with all security policies and all operational procedures, including but not limited to the tasks specified in this requirement.
12.4.2.b Additional testing procedure for service provider assessments only: Interview responsible personnel and examine records of reviews to verify that reviews are performed: • At least once every three months. • By personnel other than those responsible for performing the given task.

Service providers only, and quarterly. This is an assurance control rather than an operational one: it does not add a task, it checks that existing tasks are being performed. Two things define it. The reviews are performed by personnel other than those responsible for performing the given task, so a team confirming its own diligence does not satisfy it. And the named tasks are specific: daily log reviews, configuration reviews for network security controls, applying configuration standards to new systems, responding to security alerts, and change-management processes, with "including but not limited to" making that a floor. Those five are chosen well, because they are the operational habits that decay quietly between assessments while the documentation stays correct.

What to prepare

  • The documented review process, showing independence and the quarterly cadence.
  • Records of the last four quarters of reviews.
  • Who performed each, and their independence from the task.
  • The list of tasks reviewed, checked against the five named.

How to implement it

1. Sample the evidence, not the process. Confirming that daily log reviews happened means looking at the review records for specific days, which is what makes this different from asking the team.

2. Rotate who reviews, and keep them off the task. Independence is a named element and a peer team is the practical answer for most organisations.

3. Cover all five named tasks each quarter. They are a floor, not a menu.

4. Fix the interval, since quarterly means four. Two reviews bunched at the end of the year meet the count and not the cadence.

Where this commonly fails

  • Teams reviewing their own performance of their own tasks.
  • Reviews performed twice a year rather than quarterly.
  • Some of the five named tasks omitted because they belong to another team.
  • A review that asks whether tasks were done rather than examining evidence that they were.

Others in section 12.4:

Control What it requires
12.4.1 Service providers: Responsibility is established by executive management for the protection of cardholder data…
12.4.2.1 Service providers: Reviews conducted in accordance with Requirement 12.4.2 are documented…

12.4.1 · All controls · 12.4.2.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.