Requirement 12: Maintain a policy that addresses information security for all personnel

This requirement is not directly related to Commerce+. Refer directly to the PCI DSS for requirements and details on how to develop your information security policies.

Important: Section 12.3.9 of the PCI-DSS requires that you develop a policy to address activation and deactivation of remote access technologies. Commerce+ does not use remote access technologies for software updates