PCI_DSS_v4Requirement 12voice-validated

PCI_DSS_v4 R12: Requirement 12

PCI_DSS_v4

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

A strong security policy sets the security tone for the whole entity and lets personnel know what is expected of them. All personnel should be aware of the sensitivity of cardholder data and their responsibilities for protecting it. Risk-assessment processes, incident response, change management, and third-party service provider oversight are covered here.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 0

MitigationWhat it doesConfidence

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-2001. The control directly addresses protecting cardholder data, preventing unauthorized exposure. 2. Personnel awareness and security policies are key to minimizing sensitive information leaks.
90%
CWE-2841. Strong security policies define and enforce proper access controls. 2. Risk assessments identify areas with improper access, ensuring remediation.
80%
CWE-3061. Security policies mandate authentication for critical functions. 2. Change management ensures new functions include proper authentication mechanisms.
70%
CWE-5481. Risk assessment identifies configurations leading to information exposure. 2. Security policies dictate secure server configurations, preventing directory listings.
70%
CWE-6681. Third-party service provider oversight ensures external resources are not exposed inappropriately. 2. Security policies define proper resource segmentation and access.
80%
CWE-7981. Personnel awareness training emphasizes secure coding practices. 2. Change management processes include code reviews to identify and remove hard-coded credentials.
70%
CWE-10041. Security policies can mandate secure cookie attributes in web applications. 2. Risk assessments identify web application vulnerabilities, including insecure cookie handling.
60%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0176 compute · voice-rubric self-validated