PCI DSS 4.0
Req 2: Secure Configurations

PCI DSS 4.0 2.2.1: 2.2.1 System configuration standards maintained

Configuration standards must be developed, implemented and maintained so that they: (a) cover every system component; (b) address all known security vulnerabilities; (c) are consistent with vendor hardening recommendations or hardening standards the industry accepts; (d) are revised whenever new vulnerability issues come to light, following Requirement 6.3.1; and (e) are used whenever new systems are set up, and are confirmed to be in place before, or right after, a component goes live in a production environment. Applicability: no special notes; applies to every assessed entity. Objective under the customized approach: every system component is set up securely and consistently consistent with vendor guidance or hardening standards the industry accepts.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 67 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CMMC 2.0 · 7 controls

ISO 27001:2022 · 5 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 8.27 Secure system architecture and engineering principles
  • 8.32 Change management
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

CIS Controls v8 · 4 controls

  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process

ISO 27002:2022 · 4 controls

  • 5.37 Documented operating procedures
  • 8.27 Secure system architecture and engineering principles
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-3 Define and establish secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations

C5 (Germany) · 3 controls

  • C5-AM-03 Commissioning of Hardware
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • C5-PSS-11 Images for Virtual Machines and Containers

FedRAMP High · 3 controls

  • CM-2 Baseline Configuration
  • CM-6 Configuration Settings
  • CM-9 Configuration Management Plan

FedRAMP Moderate · 3 controls

  • CM-2 Baseline Configuration
  • CM-6 Configuration Settings
  • CM-9 Configuration Management Plan

NIST SP 800-161 Rev 1 · 3 controls

  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • SEC01-BP06 Automate deployment of standard security controls
  • SEC06-BP02 Provision compute from hardened images
  • CFTC-SS-4 Systems Operations Category
  • CFTC-SS-7 Generally Accepted Standards and Best Practices

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.14.4e Refresh Systems and Components from a Trusted Baseline
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software
  • P1-3.2.3 P1-3.2.3 Configuration standards defined and applied to every 3DS system type
  • P1-3.2.4 P1-3.2.4 Standards cover known weaknesses and follow hardening benchmarks
  • E8-UAH-ML2 User Application Hardening - Maturity Level 2
  • AUCDR-IS-2 Secure the network and systems within the data environment

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

UK Cyber Essentials · 1 control

  • CE-SC.1 Remove or Disable Unused Software

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 2: Secure Configurations

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 2.2.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 67 it maps to, and the evidence behind each claim, over MCP and REST.