PCI_DSS_v4Requirement 12voice-validated
PCI_DSS_v4 R12: Requirement 12
PCI_DSS_v4
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
A strong security policy sets the security tone for the whole entity and lets personnel know what is expected of them. All personnel should be aware of the sensitivity of cardholder data and their responsibilities for protecting it. Risk-assessment processes, incident response, change management, and third-party service provider oversight are covered here.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 0
| Mitigation | What it does | Confidence |
|---|
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-200 | 1. The control directly addresses protecting cardholder data, preventing unauthorized exposure. 2. Personnel awareness and security policies are key to minimizing sensitive information leaks. | 90% |
| CWE-284 | 1. Strong security policies define and enforce proper access controls. 2. Risk assessments identify areas with improper access, ensuring remediation. | 80% |
| CWE-306 | 1. Security policies mandate authentication for critical functions. 2. Change management ensures new functions include proper authentication mechanisms. | 70% |
| CWE-548 | 1. Risk assessment identifies configurations leading to information exposure. 2. Security policies dictate secure server configurations, preventing directory listings. | 70% |
| CWE-668 | 1. Third-party service provider oversight ensures external resources are not exposed inappropriately. 2. Security policies define proper resource segmentation and access. | 80% |
| CWE-798 | 1. Personnel awareness training emphasizes secure coding practices. 2. Change management processes include code reviews to identify and remove hard-coded credentials. | 70% |
| CWE-1004 | 1. Security policies can mandate secure cookie attributes in web applications. 2. Risk assessments identify web application vulnerabilities, including insecure cookie handling. | 60% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0176 compute · voice-rubric self-validated