PCI DSS 4.1.2: Roles and responsibilities for performing activities in Requirement 4 are documented, assigned
PCI DSS v4.0.1 control 4.1.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 4.1.
Requirement 4: Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks › Section 4.1
Roles and responsibilities for performing activities in Requirement 4 are documented, assigned, and understood.
Summary
Write down who is responsible for each transport-encryption activity, tell them, and be able to show they understood.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 4.1.2.a | Examine documentation to verify that descriptions of roles and responsibilities for performing activities in Requirement 4 are documented and assigned. |
| 4.1.2.b | Interview personnel with responsibility for performing activities in Requirement 4 to verify that roles and responsibilities are assigned as documented and are understood. |
The split between 4.1.2.a and 4.1.2.b is the whole point of this control. The first examines your documentation; the second interviews the people named in it. Assigning a responsibility in a document to somebody who does not know they hold it fails this control, and it is a common finding because the RACI is written once and staff change.
What to prepare
- A responsibility matrix naming, by role, who performs each Requirement 4 activity.
- Evidence the assignment reached the person: an acceptance, a job description, or a team charter.
- Named cover for each responsibility, so the control does not rest on one individual.
How to implement it
1. Assign by role, not by person. "The Platform Engineering on-call rota" survives a resignation; "Priya" does not. Keep a current mapping from role to people alongside it.
2. Cover the whole lifecycle, not just the interesting part. Certificate renewal, TLS configuration changes, monitoring for expiry, and responding to a certificate incident are separate activities and often land with different teams.
3. Make it visible where the work happens. A matrix that lives only in the compliance folder will not survive the interview in 4.1.2.b. Put it where the engineers already look.
Where this commonly fails
- The matrix names a team that has since been reorganised out of existence.
- Everything is assigned to "Security", including work that only the platform team can actually do.
- Nobody is assigned to notice an expiring certificate, so the responsibility exists only after an outage.
Related controls
Others in section 4.1:
| Control | What it requires |
|---|---|
| 4.1.1 | All security policies and operational procedures that are identified in Requirement 4… |
← 4.1.1 · All controls · 4.2.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.