PCI DSS 12.6.3.2: Security awareness training includes awareness about the acceptable use of end-user

PCI DSS v4.0.1 control 12.6.3.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.6.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.6

Security awareness training includes awareness about the acceptable use of end-user technologies in accordance with Requirement 12.2.1.

Summary

Security awareness training also covers the acceptable use policy for end-user technologies.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.6.3.2 Examine security awareness training content to verify it includes awareness about acceptable use of end-user technologies in accordance with Requirement 12.2.1.

Short, and it exists to close a loop that otherwise stays open. 12.2.1 requires an acceptable use policy with approved products and defined acceptable uses; this requires that people are taught it. A policy nobody has been trained on is a document that will be breached in good faith, particularly the approved-products element, because using an unapproved tool rarely feels like a policy decision to the person doing it. The procedure examines training content in accordance with Requirement 12.2.1, so the training has to reflect what that policy actually says: if the policy has no approved products list, the training cannot teach one, which is one way a gap in 12.2.1 surfaces here as well.

What to prepare

  • Training content covering acceptable use.
  • The acceptable use policy from 12.2.1, to check the training matches it.
  • Delivery records.
  • How the training is updated when the policy or the product list changes.

How to implement it

1. Teach the approved products list, not just the principles. It is the element people breach without realising, and naming what is approved is more useful than describing what is acceptable.

2. Keep the two in step. When the policy changes the training is stale, and the procedure compares them.

3. Cover cloud services explicitly. Signing up for a tool with a work email is the most common unapproved-technology decision and the least likely to feel like one.

4. Fix 12.2.1 first if it is incomplete, since training can only teach what the policy says.

Where this commonly fails

  • Acceptable use mentioned in the policy and absent from the training.
  • Training describing a policy that has since changed.
  • The approved products element skipped because the policy does not have one.
  • Cloud and personal-device use unaddressed, which is where the breaches happen.

This control refers to 12.2.1.

Others in section 12.6:

Control What it requires
12.6.1 A formal security awareness program is implemented to make all personnel aware of the entity’s…
12.6.2 The security awareness program…
12.6.3 Personnel receive security awareness training…
12.6.3.1 Security awareness training includes awareness of threats and vulnerabilities that could impact…

12.6.3.1 · All controls · 12.7.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.