PCI DSS 4.0
Req 1: Network Security Controls

PCI DSS 4.0 1.5.1: 1.5.1 Security controls on dual-connected devices

Any computing device, whether owned by the company or by an employee, that connects both to untrusted networks (the internet included) and to the CDE must have security controls where: (a) specific configuration settings are defined to stop threats entering the entity's network; (b) the security controls are actively running; and (c) users of the device cannot change the controls unless management has documented and authorised it case by case for a limited time. Applicability: controls may be disabled temporarily only for a legitimate technical need with case-by-case management authorisation, formally approved, and extra measures may be needed while they are off; this covers both employee-owned and company-owned devices. Customized approach objective: devices that touch untrusted environments and the CDE cannot bring threats into the CDE.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 52 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 6 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-4.5 Implement and Manage a Firewall on End-User Devices

ISO 27001:2022 · 6 controls

  • 6.7 Remote working
  • 8.1 User end point devices
  • 8.20 Networks security
  • 8.22 Segregation of networks
  • 8.7 Protection against malware
  • 8.9 Configuration management

ISO 27002:2022 · 6 controls

  • 6.7 Remote working
  • 8.1 User endpoint devices
  • 8.20 Networks security
  • 8.22 Segregation of networks
  • 8.7 Protection against malware
  • 8.9 Configuration management

NIST SP 800-53 Rev 5 · 6 controls

  • ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment
  • ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations
  • ANSSI-HYG-27 Prohibit Internet Access from Administration Workstations and Servers
  • ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working
  • ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals

FedRAMP High · 4 controls

  • AC-19 Access Control for Mobile Devices
  • IA-3 Device Identification and Authentication
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SC-7(7) Split Tunneling for Remote Devices

FedRAMP Moderate · 4 controls

  • AC-19 Access Control for Mobile Devices
  • IA-3 Device Identification and Authentication
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SC-7(7) Split Tunneling for Remote Devices

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-26 Software firewall - outbound (Very Good)

CMMC 2.0 · 2 controls

ISO 27701:2019 · 1 control

  • 6.3.2 Mobile devices and teleworking
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • 03.01.18 Access Control for Mobile Devices

NIST SP 800-172 · 1 control

  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources

UK Cyber Essentials · 1 control

  • CE-FW.6 Host-Based Firewall for Remote Workers

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 1: Network Security Controls

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 1.5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 52 it maps to, and the evidence behind each claim, over MCP and REST.