Regulation
PCI DSS v4.0.1
PCI DSS v4.0.1
12 requirements · 10 connected unified controls
Open PCI DSS v4.0.1 in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
PCI DSS v4.0.1
| Requirement | Unified control and mapping |
|---|---|
| PCI-Req1Install and maintain network security controls | UC-CONFIG-01 — Harden systems to approved secure configuration baselinesPartial Remaining requirement: also mandates dedicated network security controls and periodic ruleset reviews |
| PCI-Req2Apply secure configurations to all system components | |
| PCI-Req3Protect stored account data | UC-CRYPTO-01 — Encrypt data at rest and in transitPartial Remaining requirement: key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope |
| PCI-Req4Protect cardholder data with strong cryptography during transmission over open, public networks | |
| PCI-Req5Protect all systems and networks from malicious software | |
| PCI-Req6Develop and maintain secure systems and software | UC-CONFIG-04 — Build security and privacy into software design and upkeepPartial Remaining requirement: also requires protections for public-facing web applications |
| PCI-Req7Restrict access to system components and cardholder data by business need to know | UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of dutiesPartial Remaining requirement: semiannual review of all user accounts and privileges (7.2.4) not covered |
| PCI-Req8Identify users and authenticate access to system components | UC-ACCESS-09 — Authenticate all users with multi-factor authenticationPartial Remaining requirement: account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls |
| PCI-Req9Restrict physical access to cardholder data | UC-ASSET-04 — Control storage media through use, storage, and destructionPartial Remaining requirement: media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control |
| PCI-Req10Log and monitor all access to system components and cardholder data | UC-LOG-01 — Log security-relevant events across all systemsPartial Remaining requirement: also requires daily review, 12-month retention, time synchronization, log protection |
| PCI-Req11Test security of systems and networks regularly | UC-VULN-02 — Test security through independent penetration exercisesPartial Remaining requirement: also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms |
| PCI-Req12Support information security with organizational policies and programs | UC-GOV-14 — Establish and maintain approved security policies and proceduresPartial Remaining requirement: also requires awareness, screening, third-party management, and incident response program elements |