SG-13—Security Roles and Responsibilities: PCI Compliance
>Control Description
Roles and responsibilities and a program charter for the governance of PCI DSS compliance within Organization are formally documented and communicated by management.
Theme
Process
Type
Preventive
Policy/Standard
Information Security Management Standard>Implementation Guidance
1. Define roles and responsibilities for PCI DSS governances which is approved by the organization's management and documented well in PCI Charter.
>Testing Procedure
1. Inspect Organization's PCI Charter and organization chart to determine that roles and responsibilities for PCI DSS governances are appropriately documented and disseminated by Organization Management.
>Audit Artifacts
E-SG-13
>Framework Mappings
Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.
Ask AI
Configure your API key to use AI features.