# Payment Card Industry Data Security Standard v4.0.1

Framework id: `pci_dss_v4`. Industry Standard. Publisher: PCI Security Standards Council. Version: 4.0.1. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.pcisecuritystandards.org/document_library/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (74, average coverage 89%)
- 1.1 Processes and mechanisms for installing and maintaining network security controls are defined and understood: SC-07, PL-01, CM-01 (85%)
- 1.2 Network security controls (NSCs) are configured and maintained: SC-07, CM-06, CM-02, AC-04, CA-09 (90%)
- 1.2.1 Configuration standards for NSC rulesets are defined, implemented, maintained: SC-07, CM-02, CM-06 (90%)
- 1.2.5 All services, protocols, and ports allowed are identified, approved, and have a defined business need: CM-07, SC-07 (95%)
- 1.2.8 Configuration files for NSCs are secured from unauthorized access and kept consistent with active network configurations: CM-06, AC-03, CM-03 (90%)
- 1.3 Network access to and from the cardholder data environment is restricted: AC-04, CA-09, SC-07 (95%)
- 1.4 Network connections between trusted and untrusted networks are controlled: SC-07 (95%)
- 1.5 Risks to the CDE from computing devices that are able to connect to both untrusted networks and the CDE are mitigated: SC-07, AC-19, AC-20 (85%)
- 2.1 Processes and mechanisms for applying secure configurations to all system components are defined and understood: CM-01, CM-02, CM-06, PL-10, PL-11 (92%)
- 2.2 System components are configured and managed securely: CM-02, CM-06, CM-07, PL-10, PL-11 (95%)
- 2.2.1 Vendor default accounts are managed: changed, removed, or disabled: CM-06, AC-02, IA-05 (90%)
- 2.2.2 Vendor default accounts are managed if used: AC-02, IA-05, CM-06 (90%)
- 2.2.5 All unnecessary functionality is removed or disabled: CM-07 (95%)
- 2.2.7 All non-console administrative access is encrypted using strong cryptography: AC-17, SC-08, SC-13 (95%)
- 3.1 Processes and mechanisms for protecting stored account data are defined and understood: SC-28, MP-01, PL-01, CM-12 (87%)
- 3.2 Storage of account data is kept to a minimum: SI-12, PM-25, CM-12 (78%)
- 3.3 Sensitive authentication data (SAD) is not stored after authorization: SI-12, SC-28, CM-13 (68%)
- 3.4 Access to displays of full PAN and ability to copy cardholder data are restricted: AC-03, AC-06, SI-19 (70%)
- 3.5 Primary account number (PAN) is secured wherever it is stored: CM-12, SC-12, SC-13, SC-28 (82%)
- 3.6 Cryptographic keys used to protect stored account data are secured: SC-12 (85%)
- 3.7 Where cryptography is used to protect stored account data, key management processes and procedures covering all aspects of the key lifecycle are defined and implemented: SC-12 (85%)
- 4.1 Processes and mechanisms for protecting cardholder data with strong cryptography during transmission over open, public networks are defined and understood: SC-08, SC-13, PL-01, CM-13 (87%)
- 4.2 PAN is protected with strong cryptography during transmission: CM-13, SC-08, SC-13 (90%)
- 5.1 Processes and mechanisms for protecting all systems and networks from malicious software are defined and understood: SI-03, SI-01, PL-01 (90%)
- 5.2 Malicious software (malware) is prevented, or detected and addressed: SC-34, SC-44, SI-03, SI-16 (95%)
- 5.3 Anti-malware mechanisms and processes are active, maintained, and monitored: SC-35, SI-03 (95%)
- 5.4 Anti-phishing mechanisms protect users against phishing attacks: AT-02, SC-07, SI-08 (80%)
- 6.1 Processes and mechanisms for developing and maintaining secure systems and software are defined and understood: SA-03, SA-01, SA-15 (90%)
- 6.2 Bespoke and custom software are developed securely: SA-03, SA-08, SA-10, SA-11, SA-15, SA-17, CM-14, SI-16 (92%)
- 6.2.1 Bespoke and custom software are developed securely: training: AT-03, SA-16 (85%)
- 6.2.3 Bespoke and custom software is reviewed prior to being released into production to identify and correct potential coding vulnerabilities: SA-11 (90%)
- 6.3 Security vulnerabilities are identified and addressed: RA-05, SI-02, SI-05 (95%)
- 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches/updates: SI-02 (95%)
- 6.4 Public-facing web applications are protected against attacks: SA-11, SC-07, SI-03 (80%)
- 6.5 Changes to all system components are managed securely: CM-03, CM-04, CM-05, SA-10 (95%)
- 7.1 Processes and mechanisms for restricting access to system components and cardholder data by business need to know are defined and understood: AC-01, AC-06, PL-01 (90%)
- 7.2 Access to system components and data is appropriately defined and assigned: AC-02, AC-03, AC-06, AC-05 (95%)
- 7.3 Access to system components and data is managed via an access control system(s): AC-03, AC-25 (90%)
- 8.1 Processes and mechanisms for identifying users and authenticating access to system components are defined and understood: IA-01, IA-02, PL-01 (90%)
- 8.2 User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle: AC-02, IA-04, IA-05 (95%)
- 8.3 Strong authentication for users and administrators is established and managed: IA-02, IA-05, SC-37 (95%)
- 8.3.6 If passwords/passphrases are used as authentication factors, minimum level of complexity requirements: IA-05 (95%)
- 8.3.9 If passwords/passphrases are used as the only authentication factor for user access, passwords/passphrases are changed at least every 90 days: IA-05 (85%)
- 8.4 Multi-factor authentication (MFA) is implemented to secure access into the CDE: IA-02, SC-37 (95%)
- 8.5 Multi-factor authentication (MFA) systems are configured to prevent misuse: IA-02 (85%)
- 8.6 Use of application and system accounts and associated authentication factors is strictly managed: AC-02, AC-06, IA-05 (85%)
- 9.1 Processes and mechanisms for restricting physical access to cardholder data are defined and understood: PE-01, PL-01 (85%)
- 9.2 Physical access controls manage entry into facilities and systems containing cardholder data: PE-02, PE-03, PE-06, PE-07, PE-08 (95%)
- 9.3 Physical access for personnel and visitors is authorized and managed: PE-02, PE-03, PE-07, PE-08 (95%)
- 9.4 Media with cardholder data is securely stored, accessed, distributed, and destroyed: MP-02, MP-03, MP-04, MP-05, MP-06, MP-07 (95%)
- 9.5 Point of interaction (POI) devices are protected from tampering and unauthorized substitution: PE-03, SR-09, SR-10, SR-11 (70%)
- 10.1 Processes and mechanisms for logging and monitoring all access to system components and cardholder data are defined and understood: AU-01, PL-01 (90%)
- 10.2 Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events: AU-02, AU-03, AU-12 (95%)
- 10.3 Audit logs are protected from destruction and unauthorized modifications: AU-09 (95%)
- 10.4 Audit logs are reviewed to identify anomalies or suspicious activity: AU-06, SI-04 (95%)
- 10.5 Audit log history is retained and available for analysis: AU-11 (95%)
- 10.6 Time-synchronization mechanisms support consistent time settings across all systems: AU-08, SC-45 (95%)
- 10.7 Failures of critical security control systems are detected, reported, and responded to promptly: AU-05, IR-04, IR-06, SC-24, SI-04 (87%)
- 11.1 Processes and mechanisms for regularly testing security of systems and networks are defined and understood: CA-01, PL-01, SC-26 (87%)
- 11.2 Wireless access points are identified and monitored, and unauthorized wireless access points are addressed: SI-04, CM-08, AC-18 (80%)
- 11.3 External and internal vulnerabilities are regularly identified, prioritized, and addressed: RA-05, SI-02, CA-09 (95%)
- 11.4 External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected: CA-08, SC-26 (90%)
- 11.5 Network intrusions and unexpected file changes are detected and responded to: SI-07, SI-04, IR-04, AU-06, CM-14, SC-35 (92%)
- 11.6 Unauthorized changes on payment pages are detected and responded to: SI-07, SI-04, CM-03, CM-14 (72%)
- 12.1 A comprehensive information security policy that governs and provides direction for protection of the entity's information assets is known and current: PL-01, PM-01, AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PS-01, RA-01, SA-01, SC-01, SI-01, PL-09 (95%)
- 12.2 Acceptable use policies for end-user technologies are defined and implemented: PL-04, AC-20 (95%)
- 12.3 Risks to the cardholder data environment are formally identified, evaluated, and managed: RA-03, PM-09, RA-02, RA-07 (92%)
- 12.4 PCI DSS compliance is managed (for service providers): CA-02, CA-07, PM-06 (70%)
- 12.5 PCI DSS scope is documented and validated: PL-02, CM-08, CA-02, CM-12 (73%)
- 12.6 Security awareness education is an ongoing activity: AT-01, AT-02, AT-03, AT-04 (95%)
- 12.7 Personnel are screened to reduce risks from insider threats: PS-03, PS-07 (90%)
- 12.8 Risk to information assets associated with third party service provider (TPSP) relationships is managed: SA-04, SA-09, SR-01, SR-03, SR-06 (85%)
- 12.9 Third-party service providers (TPSPs) support their customers' PCI DSS compliance (for TPSPs): SA-09, SR-01 (60%)
- 12.10 Suspected and confirmed security incidents that could impact the CDE are responded to immediately: IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09 (92%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=pci_dss_v4
- Control-to-clause mappings as JSON: /api/v1/frameworks/pci_dss_v4?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/pci-dss-v4.json
- Page for people: /frameworks/pci-dss-v4/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
