Skip to content
11 min read

Requirement 1.1.2: Assigning Accountability for Network Security Controls

Requirement 1.1.2 emphasizes accountability. PCI DSS requires organizations to clearly designate individuals responsible for performing and overseeing the network security activities specified in Requirement 1. Without formal assignment of responsibilities, critical tasks such as firewall reviews, network security monitoring, change approvals, and segmentation activities may be neglected or executed inconsistently.

To achieve compliance with this requirement, organizations must document responsibility assignments, communicate these assignments to relevant personnel, and ensure that individuals understand the specific activities for which they are accountable. Documentation may include policies, procedures, job descriptions, or responsibility assignment matrices.

During an assessment, organizations are expected to provide documentation identifying the individuals responsible for Requirement 1 activities. Additionally, organizations must demonstrate through interviews that assigned personnel understand and fulfill their documented responsibilities. 

 

Requirement Information

Parent Requirement 1.1

Processes and mechanisms for installing and maintaining network security controls are defined and understood.

PCI DSS Requirement 1.1.2

Roles and responsibilities for performing activities in Requirement 1 are documented, assigned, and understood.

Priority: 6

Priority Meaning: Complete remaining compliance efforts, and ensure all controls are in place. This milestone completes PCI DSS requirements and finishes all remaining related policies, procedures, and processes needed to protect the cardholder data environment. 

 

Requirement 1.1.2 stipulates that organizations must formally define the individuals or roles responsible for activities associated with PCI DSS Requirement 1. Performing network security activities does not fulfill this requirement. Organizations are required to identify the personnel responsible for these activities, establish clear accountability, and ensure that these individuals understand their specific duties.

The purpose of this requirement is to eliminate ambiguity regarding ownership of network security processes. Critical activities such as firewall management, rule reviews, network segmentation validation, change approvals, and exception management must have clearly assigned owners. Absence of defined responsibility may lead to delays, omissions, or inconsistent execution of essential security activities.

To comply with Requirement 1.1.2, organizations must demonstrate that network security responsibilities are documented, assigned to designated personnel or roles, and clearly understood by those responsible for their execution. 

 

Why This Requirement Exists

Organizations frequently invest significant resources in developing technical controls, but often fail to clearly define ownership. Consequently, routine security activities may be neglected, required approvals omitted, changes left unreviewed, and security issues may remain unresolved.

Requirement 1.1.2 establishes accountability for activities specified in Requirement 1. Clearly assigning responsibilities allows organizations to implement a repeatable operating model, which supports the ongoing effectiveness of network security controls.

For example, if a firewall rule review is required every six months, the organization must identify the following:

  • The individual or team assigned to conduct the review.
  • The party authorized to approve the results of the review.
  • The entity accountable for resolving any identified issues.
  • The individual or group responsible for verifying that the process has been completed.

Without documented ownership, these activities are likely to be overlooked. 

Applicability of the Self-Assessment Questionnaire (SAQ)

PCI DSS Requirement 1.1.2 is included in the following Self-Assessment Questionnaires (SAQs):

SAQ D (Merchant)

This questionnaire is intended for merchants that are ineligible for other SAQ types or maintain a complex cardholder data environment requiring a comprehensive assessment.

Rationale for inclusion: Organizations completing SAQ D must maintain documented governance practices for PCI DSS controls, including assigning responsibility for network security activities.

SAQ D for Service Providers

This questionnaire is intended for service providers that store, process, transmit, or otherwise impact the security of cardholder data on behalf of other organizations.

Rationale for inclusion: Service providers often involve multiple teams in network security operations. Clearly defined responsibilities ensure consistent maintenance of security controls across all services provided.

 

Scope

Requirement 1.1.2 applies to personnel, processes, and activities tasked with implementing and maintaining network security controls that protect cardholder data and systems associated with the Cardholder Data Environment (CDE).

PCI DSS requirements apply to the Cardholder Data Environment (CDE), which comprises the following elements:

  • System components, personnel, and processes that store, process, or transmit cardholder data or sensitive authentication data.
  • System components that do not store, process, or transmit cardholder data or sensitive authentication data but have unrestricted connectivity to systems that perform these functions.

In addition, PCI DSS requirements extend to the following:

  • System components, personnel, and processes that may impact the security of cardholder data or sensitive authentication data.

Definition of Cardholder Data Environment (CDE)

Personnel, systems, networks, and processes involved in storing, processing, transmitting, or protecting payment card data.

Examples include payment applications, firewalls, network security controls, payment databases, administrators, and supporting procedures. 

 

Understanding the Requirement

Requirement 1.1.2 establishes three primary expectations.

Documentation of Responsibilities

Organizations must formally document the roles accountable for network security activities. Documentation may exist within:

  • Policies
  • Standards
  • Procedures
  • Job descriptions
  • Responsibility matrices
  • Governance documentation

The method of documentation is less important than ensuring that responsibilities are explicitly defined and easily accessible.

Assignment of Responsibilities

Beyond documenting responsibilities; they must be assigned to specific individuals, teams, or business roles. Examples include:

  • Firewall Administrator
  • Network Engineer
  • Security Analyst
  • IT Manager
  • Information Security Officer
  • Change Advisory Board

Responsibilities must be defined with enough specificity to remove any ambiguity regarding ownership.

Comprehension of Responsibilities

Personnel must demonstrate a clear understanding of their assigned responsibilities.

During an assessment, a Qualified Security Assessor (QSA) may interview individuals responsible for Requirement 1 activities and request descriptions of the following:

  • Their responsibilities.
  • Activities they perform.
  • Approval obligations.
  • Review requirements.
  • Escalation procedures.

If personnel are unable to articulate their assigned responsibilities, the assessor may determine that the requirement is not being fulfilled. 

 

Additional Technical Details

A responsibility assignment matrix is widely regarded as an effective method for documenting organizational responsibilities.

Definition: Responsibility Assignment Matrix

A responsibility assignment matrix specifies the individuals who are responsible, accountable, consulted, and informed for specific activities.

For example, a matrix can indicate that a Network Engineer is responsible for reviewing firewall rules, the IT Director is accountable for approval, the Security Officer is consulted, and affected departments are informed.

The RACI matrix is a commonly used type of responsibility assignment matrix.

Definition: RACI Matrix

The RACI matrix is a responsibility model that identifies individuals as Responsible, Accountable, Consulted, or Informed for a given task or process.

For instance, a firewall change can designate the Network Engineer as Responsible, the IT Manager as Accountable, security personnel as Consulted, and affected business units as Informed.

Organizations frequently use RACI matrices to clarify task ownership and reduce confusion during audits and operational processes. 

 

Ways to Meet Requirement 1.1.2

Organizations may employ several practical approaches to satisfy this requirement.

Option 1: Include Responsibilities Within Policies

Security policies may explicitly define responsibility assignments. For example:

The Information Security Officer is responsible for maintaining network security standards.
Network Administrators are responsible for implementing firewall configuration changes.

This approach is generally adequate for smaller organizations.

Option 2: Use Procedures to Define Responsibilities

Individual procedures may delineate responsibility assignments at each operational step. Example:

  • Network Engineer performs firewall review.
  • Security Manager reviews findings.
  • IT Director approves corrective actions.

This method may provide greater operational detail, but increases ongoing documentation maintenance.

Option 3: Develop a Responsibility Matrix

A centralized responsibility matrix functions as a single reference for maintaining ownership of Requirement 1 activities. Common activities documented may include:

  • Firewall configuration
  • Rule reviews
  • Network monitoring
  • Segmentation validation
  • Change management
  • Exception approval

This format is typically the most accessible for assessor review and provides a single document requiring updates as personnel changes occur.

Option 4: Obtain Personnel Acknowledgement

Organizations may require personnel to formally acknowledge their assigned duties. Examples include:

  • Policy acknowledgements
  • Annual certifications
  • Learning management systems
  • Responsibility acceptance forms

This process offers supplementary evidence that personnel comprehend their assigned roles. 

 

Compensating Controls and Customized Approaches

Customized Approach Objective

PCI DSS establishes the following customized approach objective:

Day-to-day responsibilities for performing all the activities in Requirement 1 are allocated. Personnel are accountable for successful, continuous operation of these requirements.

Organizations utilizing a customized approach must demonstrate that responsibilities are both clearly assigned and understood, irrespective of the governance methods in use.

Potential customized approaches may include:

  • Automated workflow systems
  • Governance software platforms
  • Task management systems
  • Integrated security operations platforms

Each customized approach must consistently demonstrate clear ownership and accountability.

Compensating Controls

Compensating controls are rarely applied to Requirement 1.1.2 because this requirement primarily addresses organizational governance and the assignment of responsibilities.

Any compensating control must offer equivalent assurance that responsibilities are formally assigned, effectively communicated, and clearly understood.

SMB Considerations

Most small and mid-sized organizations can fulfill this requirement through straightforward documentation.

A spreadsheet, responsibility matrix, policy section, or documented procedure that assigns ownership is typically sufficient if it is properly maintained and communicated.

Complex governance tools are rarely required. 

 

Demonstrating Compliance

Organizations should ensure that responsibilities are thoroughly documented, assigned to designated individuals, and fully understood across all relevant levels. Examples of baseline evidence include the following:

  • Policies identifying responsible roles
  • Procedures identifying task ownership
  • Job descriptions
  • Organizational charts
  • Responsibility assignment matrices
  • Governance documentation


Enhanced Evidence for Demonstrating Compliance Maturity

Organizations demonstrating advanced compliance maturity typically maintain the following forms of evidence:

  • Formal RACI matrices
  • Signed acknowledgements
  • Training records
  • Responsibility reviews
  • Governance committee records
  • Management approvals
  • Responsibility change tracking


Frequently Missing Evidence in Compliance Assessments

Compliance assessors frequently identify the following deficiencies:

  • Undocumented responsibility assignments
  • Outdated job responsibilities
  • Personnel unaware of assigned duties
  • Shared responsibilities without accountability
  • Governance documents that do not reflect current staffing

 

Testing Procedures

PCI DSS Testing Procedure 1.1.2.a

Examine documentation to verify that descriptions of roles and responsibilities for performing activities in Requirement 1 are documented and assigned.

Using This Testing Procedure

Internal Audit, Compliance, Information Security, and IT leadership can use this testing procedure as a self-assessment exercise by reviewing documentation and asking the following questions:

  • Have responsibilities for all Requirement 1 activities been documented?
  • Do documents clearly identify who is responsible for each activity?
  • Is accountability assigned to specific roles rather than broad departments?
  • Are assigned responsibilities consistent across policies, standards, procedures, job descriptions, and governance documents?
  • Have responsibility assignments been updated to reflect current personnel and organizational structure?

This review assists in identifying ownership gaps prior to an assessment. Organizations often find that responsibilities are implied rather than formally documented, which increases assessment risk and operational ambiguity.

Evidence Commonly Reviewed

Examples of documentation that may be reviewed include:

  • Information security policies
  • Network security policies
  • Firewall management procedures
  • Network administration procedures
  • Responsibility assignment matrices
  • RACI matrices
  • Job descriptions
  • Organization charts
  • Governance committee charters
  • Responsibility assignment records

Common Issues Identified

Internal reviews commonly reveal the following issues:

  • Undocumented responsibility assignments
  • Responsibilities assigned to departments rather than roles
  • Conflicting ownership across multiple documents
  • Outdated assignments following personnel changes
  • Missing ownership for specific Requirement 1 activities

PCI DSS Testing Procedure 1.1.2.b

Interview personnel responsible for performing activities in Requirement 1 to verify that roles and responsibilities are assigned as documented and are understood.

Using This Testing Procedure

Internal Audit, Compliance, and management personnel may conduct interviews with individuals responsible for Requirement 1 activities prior to a PCI assessment.

The objective is to verify that personnel understand their assigned responsibilities and execute these responsibilities in practice.

Sample questions may include:

  • What network security activities are you responsible for?
  • What approvals are you required to provide?
  • How frequently do you perform required reviews?
  • What documentation are you expected to maintain?
  • How do you know when a required activity must be completed?
  • Who is responsible if you are unavailable?

Responses must correspond with documented responsibility assignments. Discrepancies between personnel descriptions and documentation may indicate ineffective governance processes within the organization.

Evidence Commonly Reviewed

Evidence supporting this testing procedure may include:

  • Training records
  • Responsibility acknowledgements
  • Policy attestations
  • Meeting minutes
  • Completed review activities
  • Change management records
  • Interview results
  • Governance reporting records

Common Issues Identified

Organizations commonly identify the following issues:

  • Personnel unaware of assigned responsibilities
  • Responsibilities being performed by someone other than the documented owner
  • Individuals unable to explain required activities
  • Shared responsibilities without a clear accountable owner
  • Informal processes replacing documented procedures

 

Common Mistakes

Assuming Responsibilities Are Self-Evident

Organizations often rely on implicit assumptions regarding ownership of responsibilities. Assessors, however, require formal documentation of assignments rather than informal agreements.

Assigning Responsibility to Departments Rather Than Individuals

Phrases such as "IT is responsible" frequently create ambiguity regarding specific accountability.

Accountability improves when ownership is assigned to specific, clearly defined roles within the organization.

Neglecting to Update Responsibility Assignments

Personnel changes, promotions, and organizational restructuring can quickly render responsibility documentation outdated or inaccurate.

Disconnecting Documentation from Operational Practices

Documented ownership should accurately correspond to current operational practices. Assessors often identify instances where assigned personnel are no longer fulfilling the documented responsibilities.

No Evidence of Personnel Awareness

Organizations may maintain comprehensive documentation of responsibilities, yet frequently lack evidence that personnel have received, reviewed, or understood these assignments.