PCI DSS 4.0 1.5.1: 1.5.1 Security controls on dual-connected devices
Any computing device, whether owned by the company or by an employee, that connects both to untrusted networks (the internet included) and to the CDE must have security controls where: (a) specific configuration settings are defined to stop threats entering the entity's network; (b) the security controls are actively running; and (c) users of the device cannot change the controls unless management has documented and authorised it case by case for a limited time. Applicability: controls may be disabled temporarily only for a legitimate technical need with case-by-case management authorisation, formally approved, and extra measures may be needed while they are off; this covers both employee-owned and company-owned devices. Customized approach objective: devices that touch untrusted environments and the CDE cannot bring threats into the CDE.
This control maps to 52 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 1.5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.