Skip to main content

💼 12.6.3 Personnel receive security awareness training.

Description​

As follows:

  • Upon hire and at least once every 12 months.
  • Multiple methods of communication are used.
  • Personnel acknowledge at least once every 12 months that they have read and understood the information security policy and procedures.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/12/06/01
    • /frameworks/pci-dss-v3.2.1/12/06/02
    • /frameworks/pci-dss-v4.0.1/12/06/03
  • Internal
    • ID: dec-c-73469de2

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 12.6.1 Educate personnel upon hire and at least annually.
💼 PCI DSS v3.2.1 → 💼 12.6.2 Require personnel to acknowledge at least annually that they have read and understood the security policy and procedures.
💼 PCI DSS v4.0.1 → 💼 12.6.3 Personnel receive security awareness training.2

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 12.6.1 Educate personnel upon hire and at least annually.
💼 PCI DSS v3.2.1 → 💼 12.6.2 Require personnel to acknowledge at least annually that they have read and understood the security policy and procedures.
💼 PCI DSS v4.0.1 → 💼 12.6.3 Personnel receive security awareness training.2

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
💼 12.6.3.1 Security awareness training includes awareness of threats and vulnerabilities that could impact the security of the CDE.
💼 12.6.3.2 Security awareness training includes awareness about the acceptable use of end-user technologies.