PCI DSS 12.7.1: Potential personnel who will have access to the CDE are screened
PCI DSS v4.0.1 control 12.7.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.7.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.7
Potential personnel who will have access to the CDE are screened, within the constraints of local laws, prior to hire to minimize the risk of attacks from internal sources.
Summary
Screen people before hiring them into roles with access to the cardholder data environment, as far as local law allows.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.7.1 | Interview responsible Human Resource department management to verify that screening is conducted, within the constraints of local laws, prior to hiring potential personnel who will have access to the CDE. |
The only control in the standard about hiring, and the qualifier is doing real work: within the constraints of local laws. What screening is permitted varies considerably by jurisdiction, and the requirement accommodates that rather than prescribing a check, so the obligation is to do what is lawful where you operate and to be able to say what that is. The procedure interviews Human Resource department management, which is unusual: this is one of very few controls assessed by talking to HR, and it is therefore one that the security function cannot answer on its own. Scope is potential personnel who will have access to the CDE, so it is not everybody, which makes the practical question one of knowing which roles those are before the offer is made rather than after.
What to prepare
- The screening process, and what it consists of in each jurisdiction you hire in.
- Which roles have CDE access, identified before hiring.
- Evidence screening happened prior to hire.
- HR management, available for interview.
How to implement it
1. Flag CDE-access roles in the requisition. The screening has to happen before hire, so the role has to be identified before the process starts.
2. Record what is lawful in each jurisdiction. The qualifier is part of the requirement, and being able to state the local constraint is the answer where a check is not permitted.
3. Include contractors and agency staff where they will have CDE access, since they reach the same systems through a different hiring route.
4. Talk to HR before the assessment. They are interviewed directly, and the process is theirs rather than security's.
Where this commonly fails
- Screening applied to permanent staff and not to contractors with the same access.
- CDE-access roles identified after hire, so screening happens late or not at all.
- No record of the local legal constraints, so an absent check cannot be explained.
- The security team answering for a process HR owns, which the interview exposes.
Related controls
← 12.6.3.2 · All controls · 12.8.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.