Payment Card Industry Data Security Standard v4.0.1
Global security standard for organisations that store, process, or transmit cardholder data. Defines 12 requirements across 6 control objectives for protecting payment card data.
AC (11) AT (4) AU (9) CA (5) CM (11) CP (1) IA (4) IR (9) MA (1) MP (7) PE (6) PL (6) PM (4) PS (3) RA (5) SA (10) SC (13) SI (10) SR (6)
AC Access Control
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| AC-01 | Policy and Procedures | 7.112.1 |
| AC-02 | Account Management | 2.2.12.2.27.28.28.6 |
| AC-03 | Access Enforcement | 1.2.83.47.27.3 |
| AC-04 | Information Flow Enforcement | 1.21.3 |
| AC-05 | Separation of Duties | 7.2 |
| AC-06 | Least Privilege | 3.47.17.28.6 |
| AC-17 | Remote Access | 2.2.7 |
| AC-18 | Wireless Access | 11.2 |
| AC-19 | Access Control for Mobile Devices | 1.5 |
| AC-20 | Use of External Systems | 1.512.2 |
| AC-25 | Reference Monitor | 7.3 |
AT Awareness and Training
AU Audit and Accountability
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| AU-01 | Policy and Procedures | 10.112.1 |
| AU-02 | Event Logging | 10.2 |
| AU-03 | Content of Audit Records | 10.2 |
| AU-05 | Response to Audit Logging Process Failures | 10.7 |
| AU-06 | Audit Record Review, Analysis, and Reporting | 10.411.5 |
| AU-08 | Time Stamps | 10.6 |
| AU-09 | Protection of Audit Information | 10.3 |
| AU-11 | Audit Record Retention | 10.5 |
| AU-12 | Audit Record Generation | 10.2 |
CA Security Assessment and Authorization
CM Configuration Management
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| CM-01 | Policy and Procedures | 1.12.112.1 |
| CM-02 | Baseline Configuration | 1.21.2.12.12.2 |
| CM-03 | Configuration Change Control | 1.2.86.511.6 |
| CM-04 | Impact Analyses | 6.5 |
| CM-05 | Access Restrictions for Change | 6.5 |
| CM-06 | Configuration Settings | 1.21.2.11.2.82.12.22.2.12.2.2 |
| CM-07 | Least Functionality | 1.2.52.22.2.5 |
| CM-08 | System Component Inventory | 11.212.5 |
| CM-12 | Information Location | 3.13.23.512.5 |
| CM-13 | Data Action Mapping | 3.34.14.2 |
| CM-14 | Signed Components | 6.211.511.6 |
CP Contingency Planning
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| CP-01 | Policy and Procedures | 12.1 |
IA Identification and Authentication
IR Incident Response
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| IR-01 | Policy and Procedures | 12.112.10 |
| IR-02 | Incident Response Training | 12.10 |
| IR-03 | Incident Response Testing | 12.10 |
| IR-04 | Incident Handling | 10.711.512.10 |
| IR-05 | Incident Monitoring | 12.10 |
| IR-06 | Incident Reporting | 10.712.10 |
| IR-07 | Incident Response Assistance | 12.10 |
| IR-08 | Incident Response Plan | 12.10 |
| IR-09 | Information Spillage Response | 12.10 |
MA Maintenance
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| MA-01 | Policy and Procedures | 12.1 |
MP Media Protection
PE Physical and Environmental Protection
PL Planning
PM Program Management
PS Personnel Security
RA Risk Assessment
SA System and Services Acquisition
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| SA-01 | Policy and Procedures | 6.112.1 |
| SA-03 | System Development Life Cycle | 6.16.2 |
| SA-04 | Acquisition Process | 12.8 |
| SA-08 | Security and Privacy Engineering Principles | 6.2 |
| SA-09 | External System Services | 12.812.9 |
| SA-10 | Developer Configuration Management | 6.26.5 |
| SA-11 | Developer Testing and Evaluation | 6.26.2.36.4 |
| SA-15 | Development Process, Standards, and Tools | 6.16.2 |
| SA-16 | Developer-provided Training | 6.2.1 |
| SA-17 | Developer Security and Privacy Architecture and Design | 6.2 |
SC System and Communications Protection
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| SC-01 | Policy and Procedures | 12.1 |
| SC-07 | Boundary Protection | 1.11.21.2.11.2.51.31.41.55.46.4 |
| SC-08 | Transmission Confidentiality and Integrity | 2.2.74.14.2 |
| SC-12 | Cryptographic Key Establishment and Management | 3.53.63.7 |
| SC-13 | Cryptographic Protection | 2.2.73.54.14.2 |
| SC-24 | Fail in Known State | 10.7 |
| SC-26 | Decoys | 11.111.4 |
| SC-28 | Protection of Information at Rest | 3.13.33.5 |
| SC-34 | Non-modifiable Executable Programs | 5.2 |
| SC-35 | External Malicious Code Identification | 5.311.5 |
| SC-37 | Out-of-band Channels | 8.38.4 |
| SC-44 | Detonation Chambers | 5.2 |
| SC-45 | System Time Synchronization | 10.6 |
SI System and Information Integrity
| Control | Name | PCI DSS v4.0.1 References |
|---|---|---|
| SI-01 | Policy and Procedures | 5.112.1 |
| SI-02 | Flaw Remediation | 6.36.3.311.3 |
| SI-03 | Malicious Code Protection | 5.15.25.36.4 |
| SI-04 | System Monitoring | 10.410.711.211.511.6 |
| SI-05 | Security Alerts, Advisories, and Directives | 6.3 |
| SI-07 | Software, Firmware, and Information Integrity | 11.511.6 |
| SI-08 | Spam Protection | 5.4 |
| SI-12 | Information Management and Retention | 3.23.3 |
| SI-16 | Memory Protection | 5.26.2 |
| SI-19 | De-identification | 3.4 |