Traffic coming into trusted networks from untrusted networks must be limited to: (a) communications with system components authorised to offer publicly accessible services, protocols and ports; (b) stateful responses to communications that system components in the trusted network started; and (c) nothing else, with all other traffic denied. Applicability: the intent concerns sessions crossing the trusted/untrusted boundary, not the details of individual protocols; UDP and other connectionless protocols may still be used if the NSC maintains state. Customized approach objective: only authorised traffic, or traffic responding to a trusted-network system component, can pass from an untrusted network into a trusted one.
This control maps to 42 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 1.4.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.