Skip to main content

πŸ’Ό 12.11 Perform reviews at least quarterly to confirm personnel are following security policies and operational procedures.

Description​

Additional requirement for service providers only.

Reviews must cover the following processes:

  • Daily log reviews
  • Firewall rule-set reviews
  • Applying configuration standards to new systems
  • Responding to security alerts
  • Change management processes

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/12/04/02
  • Internal
    • ID: dec-c-663edf0d

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 12.4.2 Reviews are performed at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 12.4.2 Reviews are performed at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 12.11.1 Maintain documentation of quarterly review process.