Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

PCI DSS Requirement 12: Maintain an Information Security Policy

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
2,604
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

PCI DSS Requirement 12 establishes the organizational policies and programs needed to protect cardholder data and manage security responsibilities across an entity. Its ten sections require a current, widely communicated information security policy; acceptable-use rules for employee technology; formal risk analyses; executive oversight of PCI DSS compliance; documented and regularly validated scope; ongoing security awareness training; personnel screening; and management of third-party service-provider risks and responsibilities. The requirement also emphasizes maintaining current technology, cryptography, asset, data-flow, and service-provider inventories, with additional review obligations for service providers. Organizations must maintain, test, and improve an incident-response plan that assigns 24/7 responders, addresses security-monitoring alerts, supports recovery and required notifications, and provides procedures for discovering payment account numbers outside the defined cardholder data environment. The source also presents Basis Theory, a PCI Level 1 compliant service provider, as a platform intended to help companies secure and tokenize card data while reducing the number of systems brought into PCI DSS scope.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.