PCI DSS v4.0
Security

Access Control Policy Template

Restricting access to cardholder data system components on a business need-to-know basis.

What This Policy Covers

Purpose and Scope-Policy objectives and applicability to CDE.
Access Control Model-Role-based access control (RBAC) and least privilege principles.
CDE Access Restrictions-Who may access cardholder data and under what conditions.
Multi-Factor Authentication Requirements-MFA for all CDE access and remote access.
User Provisioning and Deprovisioning-Joiner/mover/leaver access lifecycle.
Privileged Access Management-Controls for administrative and privileged accounts.
Access Reviews-Quarterly access recertification process.

Required Sections

A compliant Access Control Policy for PCI DSS v4.0 must include the following7 sections. Each section addresses a specific control requirement that auditors will review.

1

Purpose and Scope

Policy objectives and applicability to CDE.

2

Access Control Model

Role-based access control (RBAC) and least privilege principles.

3

CDE Access Restrictions

Who may access cardholder data and under what conditions.

4

Multi-Factor Authentication Requirements

MFA for all CDE access and remote access.

5

User Provisioning and Deprovisioning

Joiner/mover/leaver access lifecycle.

6

Privileged Access Management

Controls for administrative and privileged accounts.

7

Access Reviews

Quarterly access recertification process.

Generate a Customized Version

This template shows the required structure. PoliWriter generates a fully customized Access Control Policy that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.