---
title: "A Beginner’s Guide to PCI DSS 4.0: Requirements 10-12"
description: Here are the PCI DSS 4.0 core requirements
image: https://insights.comforte.com/hubfs/comforte%20AG_A%20Beginners%20Guide%20to%20PCI%20DSS%204.00_%20Requirements%2010-12%20_21.11.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - A Beginner’s Guide to PCI DSS 4.0: Requirements 10-12](https://insights.comforte.com/hubfs/comforte%20AG_A%20Beginners%20Guide%20to%20PCI%20DSS%204.00_%20Requirements%2010-12%20_21.11.png)](https://insights.comforte.com/a-beginners-guide-to-pci-dss-4.0-requirements-10-12)

[Mirza Salihagic](https://insights.comforte.com/author/mirza-salihagic) l Nov 21, 2024 l [PCI DSS](https://insights.comforte.com/tag/pci-dss), [Compliance](https://insights.comforte.com/tag/compliance)

# A Beginner’s Guide to PCI DSS 4.0: Requirements 10-12

PCI DSS 4.0 was designed 20 years ago to help reduce the risk of major breaches of card data at financial services firms, retailers and others that store, process and transmit this information. As the emergence of AI tooling and a sophisticated cybercrime supply chain tilt the advantage in threat actors’ favor, the best practice security steps mandated by the standard are more relevant today than ever. Yet compliance can take significant time and effort.

To help organizations understand where to start, we put together this three-part blog series, outlining the six control objectives and 12 requirements of PCI DSS 4.0. In the final part, we highlight Requirements 10-12, and show how comforte can help:

## Regularly Monitor and Test Networks

### Requirement 10: Log and monitor all access to system components and cardholder data

Perimeter defences are one thing. But increasingly, threat actors are able to infiltrate networks quite easily *en route* to card data. This is where logging and monitoring come in, alerting security teams to suspicious activity before malicious actors can cause any damage. PCI DSS mandates the presence of system activity logs on all system components and in the cardholder data environment (CDE). It should apply to all relevant employee, contractor, consultant, and internal/external vendor activities, as well as those of other third parties.

### Requirement 11: Test security of systems and networks regularly

The number of vulnerabilities (CVEs) discovered and published each year continues to break all records. Last year, it reached nearly 29,000. That’s not to mention those discovered by threat actors that have yet to be shared with vendors. That’s why PCI DSS requires system components, processes and custom software to be tested frequently to ensure security controls remain effective.

## Maintain an Information Security Policy

### Requirement 12: Support information security with organizational policies and programs

Policy matters. It is the unsung hero of information security which effectively articulates the security culture of the entire organization. It informs employees what they are expected to do and how they are expected to act from a cybersecurity perspective. This final PCI DSS 4.0 requirement mandates that all employees are aware of the sensitivity of payment account data and their responsibilities to protect it. It extends to any relevant full-, part-time and temporary employees, contractors and consultants. That means anyone with responsibility for protecting card data or anyone whose role may impact the security of data.

## How comforte can help

No technology can magically enable PCI DSS 4.0 compliance. However, the comforte SecureDPS solution offers organizations a helping hand which could enable them to reduce the time, cost and effort associated with the process. At a high level, it’s an enterprise-grade data protection platform that delivers:

- Continuous data discovery and classification to uncover cardholder data wherever it resides in the organization
- Strong protection of cardholder data in line with PCI DSS requirements, via format-preserving encryption, tokenization and other methods—during transmission over open, public networks
- Restricted access to cardholder data to authorized personnel only

An [independent analysis](https://insights.comforte.com/how-comfortes-securedps-can-support-your-pci-dss-4.0-plans?hsLang=en) of the SecureDPS solution by Coalfire confirms that it supports PCI DSS 4.0 compliance in the following ways:

**Requirement 10:**

10.2 Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.

10.3 Audit logs are protected from destruction and unauthorized modifications.

10.5 Audit log history is retained and available for analysis.

**Requirement 12:**

12.3 Targeted risks to the cardholder data environment are formally identified, evaluated and managed.

12.5 PCI DSS scope is documented and validated.

Comforte SecureDPS is already helping some of the world’s largest and most demanding financial institutions streamline their PCI DSS 4.0 compliance programs.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/a-beginners-guide-to-pci-dss-4.0-requirements-10-12&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/a-beginners-guide-to-pci-dss-4.0-requirements-10-12&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/a-beginners-guide-to-pci-dss-4.0-requirements-10-12&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/a-beginners-guide-to-pci-dss-4.0-requirements-10-12&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/a-beginners-guide-to-pci-dss-4.0-requirements-10-12&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Curious about the latest in PCI DSS v4.0?

Our latest document offers a quick, essential overview of key changes and insights, along with strategies for reducing PCI audit scope. It’s a must-read for anyone managing PCI compliance and looking to streamline their efforts. Don’t miss out—download now to stay informed!

[![Download the Complete Guide](https://no-cache.hubspot.com/cta/default/4026697/0f9117c6-6ddc-43f0-b027-c01ac36c270a.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/0f9117c6-6ddc-43f0-b027-c01ac36c270a)

### Related posts

![How Vaultless Tokenization Works in Practice, to Transform Your Business](https://insights.comforte.com/hubfs/comforte%20AG_How%20Vaultless%20Tokenization%20Works%20in%20Practice%20to%20Transform%20Your%20Business_24.07.2025.png)

 Jul 24, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [How Vaultless Tokenization Works in Practice, to Transform Your Business](https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business?hsLang=en)

In last month’s [blog post](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en) we explained how vaultless tokenization can transform PCI DSS 4.0 compliance from a regulatory burden into a business enabler. Not only does vaultless tokenization reduce the scope and cost of compliance, but it also...

[Read more](https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business?hsLang=en)

![Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/hubfs/comforte%20AG_Is%20PCI%20DSS%204.0%20Slowing%20You%20Down_%20Heres%20How%20comforte%20Can%20Accelerate%20Your%20PCI%20Compliance%20Journey%20.png)

 Jun 26, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

With the latest version of PCI DSS, the Payment Card Industry Security Standards Council (PCI SSC) aims to elevate the standards for cardholder data (CHD) security with themes like stronger cryptography, multi-factor authentication, and continuous...

[Read more](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

![The PCI DSS 4.0 Deadline Has Passed, But There’s Still Time to Play Catchup](https://insights.comforte.com/hubfs/comforte%20AG_The%20PCI%20DSS%204.0%20Deadline%20Has%20Passed_%20But%20There%E2%80%99s%20Still%20Time%20to%20Play%20Catchup.png)

 Apr 17, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [The PCI DSS 4.0 Deadline Has Passed, But There’s Still Time to Play Catchup](https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup?hsLang=en)

The deadline for PCI DSS 4.0 has been and gone. But it’s never too late to advance compliance plans. It’s not just about avoiding potentially large fines and other penalties. Following the standard to the letter helps ensure organizations are...

[Read more](https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>