Personnel
PCIComplianceHubLast updated
Everyone working for an entity who has security responsibilities for account data or who could affect its security: full-time and part-time employees, temporary staff, contractors and consultants. The word is chosen so that no requirement about people stops at the payroll boundary.
Applies to. Every entity. Requirements 8, 9 and 12 in particular are written to personnel, and the definition is what puts contractors inside them.
Example. A contractor with a badge to the server room and a consultant with a VPN account are personnel: 9.3.1 governs their physical access, 8.2.1 requires each to have their own user ID, and 12.6.3 requires them to receive security awareness training on hire and at least annually.
Limits. Personnel are not visitors, and the standard keeps the two apart: a visitor is escorted and logged (9.3.2, 9.3.3); personnel are authorised, identified and revoked when they leave (9.3.1). Personnel with access to cardholder data are also subject to screening before hire (12.7.1), within the limits of local law. A third party's staff working under the entity's direction are the entity's personnel for these purposes; a third party working under its own direction is a TPSP.