Skip to main content

πŸ’Ό 12.4.2 Reviews are performed at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures

  • Contextual name: πŸ’Ό 12.4.2 Reviews are performed at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures

  • ID: /frameworks/pci-dss-v4.0.1/12/04/02

  • Located in: πŸ’Ό 12.4 PCI DSS compliance is managed.

Description​

Additional requirement for service providers only.

Include, but are not limited to, the following tasks:

  • Daily log reviews.
  • Configuration reviews for network security controls.
  • Applying configuration standards to new systems.
  • Responding to security alerts.
  • Change-management processes.

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/12/04/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 12.4.2 Reviews are performed at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 12.4.2 Reviews are performed at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 12.4.2.1 Reviews conducted in accordance with Requirement 12.4.2 are documented.