By: Derek Rogers on Oct 5, 2026, 12:50:57 PM
Requirement 1.1.2 emphasizes accountability. PCI DSS requires organizations to clearly designate individuals responsible for performing and overseeing the network security activities specified in Requirement 1. Without formal assignment of responsibilities, critical tasks such as firewall reviews, network security monitoring, change approvals, and segmentation activities may be neglected or executed inconsistently.
To achieve compliance with this requirement, organizations must document responsibility assignments, communicate these assignments to relevant personnel, and ensure that individuals understand the specific activities for which they are accountable. Documentation may include policies, procedures, job descriptions, or responsibility assignment matrices.
During an assessment, organizations are expected to provide documentation identifying the individuals responsible for Requirement 1 activities. Additionally, organizations must demonstrate through interviews that assigned personnel understand and fulfill their documented responsibilities.
Parent Requirement 1.1
Processes and mechanisms for installing and maintaining network security controls are defined and understood.
PCI DSS Requirement 1.1.2
Roles and responsibilities for performing activities in Requirement 1 are documented, assigned, and understood.
Priority: 6
Priority Meaning: Complete remaining compliance efforts, and ensure all controls are in place. This milestone completes PCI DSS requirements and finishes all remaining related policies, procedures, and processes needed to protect the cardholder data environment.
Requirement 1.1.2 stipulates that organizations must formally define the individuals or roles responsible for activities associated with PCI DSS Requirement 1. Performing network security activities does not fulfill this requirement. Organizations are required to identify the personnel responsible for these activities, establish clear accountability, and ensure that these individuals understand their specific duties.
The purpose of this requirement is to eliminate ambiguity regarding ownership of network security processes. Critical activities such as firewall management, rule reviews, network segmentation validation, change approvals, and exception management must have clearly assigned owners. Absence of defined responsibility may lead to delays, omissions, or inconsistent execution of essential security activities.
To comply with Requirement 1.1.2, organizations must demonstrate that network security responsibilities are documented, assigned to designated personnel or roles, and clearly understood by those responsible for their execution.
Organizations frequently invest significant resources in developing technical controls, but often fail to clearly define ownership. Consequently, routine security activities may be neglected, required approvals omitted, changes left unreviewed, and security issues may remain unresolved.
Requirement 1.1.2 establishes accountability for activities specified in Requirement 1. Clearly assigning responsibilities allows organizations to implement a repeatable operating model, which supports the ongoing effectiveness of network security controls.
For example, if a firewall rule review is required every six months, the organization must identify the following:
- The individual or team assigned to conduct the review.
- The party authorized to approve the results of the review.
- The entity accountable for resolving any identified issues.
- The individual or group responsible for verifying that the process has been completed.
Without documented ownership, these activities are likely to be overlooked.
Applicability of the Self-Assessment Questionnaire (SAQ)
PCI DSS Requirement 1.1.2 is included in the following Self-Assessment Questionnaires (SAQs):
SAQ D (Merchant)
This questionnaire is intended for merchants that are ineligible for other SAQ types or maintain a complex cardholder data environment requiring a comprehensive assessment.
Rationale for inclusion: Organizations completing SAQ D must maintain documented governance practices for PCI DSS controls, including assigning responsibility for network security activities.
SAQ D for Service Providers
This questionnaire is intended for service providers that store, process, transmit, or otherwise impact the security of cardholder data on behalf of other organizations.
Rationale for inclusion: Service providers often involve multiple teams in network security operations. Clearly defined responsibilities ensure consistent maintenance of security controls across all services provided.
Requirement 1.1.2 applies to personnel, processes, and activities tasked with implementing and maintaining network security controls that protect cardholder data and systems associated with the Cardholder Data Environment (CDE).
PCI DSS requirements apply to the Cardholder Data Environment (CDE), which comprises the following elements:
In addition, PCI DSS requirements extend to the following:
Definition of Cardholder Data Environment (CDE)
Personnel, systems, networks, and processes involved in storing, processing, transmitting, or protecting payment card data.
Examples include payment applications, firewalls, network security controls, payment databases, administrators, and supporting procedures.
Requirement 1.1.2 establishes three primary expectations.
Documentation of Responsibilities
Organizations must formally document the roles accountable for network security activities. Documentation may exist within:
- Policies
- Standards
- Procedures
- Job descriptions
- Responsibility matrices
- Governance documentation
The method of documentation is less important than ensuring that responsibilities are explicitly defined and easily accessible.
Assignment of Responsibilities
Beyond documenting responsibilities; they must be assigned to specific individuals, teams, or business roles. Examples include:
- Firewall Administrator
- Network Engineer
- Security Analyst
- IT Manager
- Information Security Officer
- Change Advisory Board
Responsibilities must be defined with enough specificity to remove any ambiguity regarding ownership.
Comprehension of Responsibilities
Personnel must demonstrate a clear understanding of their assigned responsibilities.
During an assessment, a Qualified Security Assessor (QSA) may interview individuals responsible for Requirement 1 activities and request descriptions of the following:
If personnel are unable to articulate their assigned responsibilities, the assessor may determine that the requirement is not being fulfilled.
A responsibility assignment matrix is widely regarded as an effective method for documenting organizational responsibilities.
Definition: Responsibility Assignment Matrix
A responsibility assignment matrix specifies the individuals who are responsible, accountable, consulted, and informed for specific activities.
For example, a matrix can indicate that a Network Engineer is responsible for reviewing firewall rules, the IT Director is accountable for approval, the Security Officer is consulted, and affected departments are informed.
The RACI matrix is a commonly used type of responsibility assignment matrix.
Definition: RACI Matrix
The RACI matrix is a responsibility model that identifies individuals as Responsible, Accountable, Consulted, or Informed for a given task or process.
For instance, a firewall change can designate the Network Engineer as Responsible, the IT Manager as Accountable, security personnel as Consulted, and affected business units as Informed.
Organizations frequently use RACI matrices to clarify task ownership and reduce confusion during audits and operational processes.
Organizations may employ several practical approaches to satisfy this requirement.
Option 1: Include Responsibilities Within Policies
Security policies may explicitly define responsibility assignments. For example:
The Information Security Officer is responsible for maintaining network security standards.
Network Administrators are responsible for implementing firewall configuration changes.
This approach is generally adequate for smaller organizations.
Option 2: Use Procedures to Define Responsibilities
Individual procedures may delineate responsibility assignments at each operational step. Example:
- Network Engineer performs firewall review.
- Security Manager reviews findings.
- IT Director approves corrective actions.
This method may provide greater operational detail, but increases ongoing documentation maintenance.
Option 3: Develop a Responsibility Matrix
A centralized responsibility matrix functions as a single reference for maintaining ownership of Requirement 1 activities. Common activities documented may include:
- Firewall configuration
- Rule reviews
- Network monitoring
- Segmentation validation
- Change management
- Exception approval
This format is typically the most accessible for assessor review and provides a single document requiring updates as personnel changes occur.
Option 4: Obtain Personnel Acknowledgement
Organizations may require personnel to formally acknowledge their assigned duties. Examples include:
- Policy acknowledgements
- Annual certifications
- Learning management systems
- Responsibility acceptance forms
This process offers supplementary evidence that personnel comprehend their assigned roles.
Customized Approach Objective
PCI DSS establishes the following customized approach objective:
Day-to-day responsibilities for performing all the activities in Requirement 1 are allocated. Personnel are accountable for successful, continuous operation of these requirements.
Organizations utilizing a customized approach must demonstrate that responsibilities are both clearly assigned and understood, irrespective of the governance methods in use.
Potential customized approaches may include:
Each customized approach must consistently demonstrate clear ownership and accountability.
Compensating Controls
Compensating controls are rarely applied to Requirement 1.1.2 because this requirement primarily addresses organizational governance and the assignment of responsibilities.
Any compensating control must offer equivalent assurance that responsibilities are formally assigned, effectively communicated, and clearly understood.
SMB Considerations
Most small and mid-sized organizations can fulfill this requirement through straightforward documentation.
A spreadsheet, responsibility matrix, policy section, or documented procedure that assigns ownership is typically sufficient if it is properly maintained and communicated.
Complex governance tools are rarely required.
Organizations should ensure that responsibilities are thoroughly documented, assigned to designated individuals, and fully understood across all relevant levels. Examples of baseline evidence include the following:
- Policies identifying responsible roles
- Procedures identifying task ownership
- Job descriptions
- Organizational charts
- Responsibility assignment matrices
- Governance documentation
Enhanced Evidence for Demonstrating Compliance Maturity
Organizations demonstrating advanced compliance maturity typically maintain the following forms of evidence:
Frequently Missing Evidence in Compliance Assessments
Compliance assessors frequently identify the following deficiencies:
PCI DSS Testing Procedure 1.1.2.a
Examine documentation to verify that descriptions of roles and responsibilities for performing activities in Requirement 1 are documented and assigned.
Internal Audit, Compliance, Information Security, and IT leadership can use this testing procedure as a self-assessment exercise by reviewing documentation and asking the following questions:
This review assists in identifying ownership gaps prior to an assessment. Organizations often find that responsibilities are implied rather than formally documented, which increases assessment risk and operational ambiguity.
Evidence Commonly Reviewed
Examples of documentation that may be reviewed include:
Common Issues Identified
Internal reviews commonly reveal the following issues:
PCI DSS Testing Procedure 1.1.2.b
Interview personnel responsible for performing activities in Requirement 1 to verify that roles and responsibilities are assigned as documented and are understood.
Using This Testing Procedure
Internal Audit, Compliance, and management personnel may conduct interviews with individuals responsible for Requirement 1 activities prior to a PCI assessment.
The objective is to verify that personnel understand their assigned responsibilities and execute these responsibilities in practice.
Sample questions may include:
Responses must correspond with documented responsibility assignments. Discrepancies between personnel descriptions and documentation may indicate ineffective governance processes within the organization.
Evidence Commonly Reviewed
Evidence supporting this testing procedure may include:
Common Issues Identified
Organizations commonly identify the following issues:
Assuming Responsibilities Are Self-Evident
Organizations often rely on implicit assumptions regarding ownership of responsibilities. Assessors, however, require formal documentation of assignments rather than informal agreements.
Assigning Responsibility to Departments Rather Than Individuals
Phrases such as "IT is responsible" frequently create ambiguity regarding specific accountability.
Accountability improves when ownership is assigned to specific, clearly defined roles within the organization.
Neglecting to Update Responsibility Assignments
Personnel changes, promotions, and organizational restructuring can quickly render responsibility documentation outdated or inaccurate.
Disconnecting Documentation from Operational Practices
Documented ownership should accurately correspond to current operational practices. Assessors often identify instances where assigned personnel are no longer fulfilling the documented responsibilities.
No Evidence of Personnel Awareness
Organizations may maintain comprehensive documentation of responsibilities, yet frequently lack evidence that personnel have received, reviewed, or understood these assignments.