← PCI DSS 4.0.1 · Req 12 — Policies and programmes

12.1 — Information security policy

high policy-governance

Requirement

An overall information security policy is established, published, maintained, disseminated to all relevant personnel and reviewed at least once every 12 months and updated as needed; roles and responsibilities for information security are defined, and a member of executive management is formally assigned responsibility.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
information security policysecurity policy
Required element 2 — any one of
reviewedannual…every 12 monthspublisheddisseminatedcommunicatedapproved
Supporting terms — specificity signals
12.1.112.1.212.1.312.1.4executiveciso

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.24 Responsibility of the controller policy-governance
GDPR Art.31 Cooperation with the supervisory authority policy-governance
SOC 2 CC5.1 Selection and development of control activities policy-governance
SOC 2 CC5.3 Deployment through policies and procedures policy-governance
ISO 27001 A.5.1 Policies for information security policy-governance
ISO 27001 A.6.4 Disciplinary process policy-governance
HIPAA 164.308(a)(1)(ii)(C) Sanction policy (R) policy-governance
NIST CSF 2.0 GV.PO-01 Cybersecurity policy is established and communicated policy-governance