The part of the standard that relates to security awareness and training is section 12.6 which requires merchants and service providers to:
Implement a formal security awareness program to make all employees aware of the importance of cardholder data security.
- Educate employees upon hire and at least annually.
- Require employees to acknowledge in writing that they have read and understood the company’s security policy and procedures.
- Merchants and service providers are also required to provide appropriate training to staff with security breach response responsibilities.
No comments:
Post a Comment