PCI DSS 4.0
Req 2: Secure Configurations

PCI DSS 4.0 2.2.7: 2.2.7 Non-console administrative access encrypted

All non-console administrative access must be encrypted with strong cryptography. The guidance explains the purpose (stopping an eavesdropper capturing administrator IDs, passwords and other authorization factors), gives out-of-band technologies such as lights-out management, IPMI and KVM switches with remote capability as examples of non-console access, and recommends that protocols not fall back to weaker, insecure versions. Applicability: this includes administrative access through application programming interfaces (APIs) and interfaces reached by browser. Objective under the customized approach: administrative authorization factors in cleartext cannot be read or captured from any network transmission.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 36 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-4.6 Securely Manage Enterprise Assets and Software

CMMC 2.0 · 3 controls

  • ANSSI-HYG-21 Use Secure Protocols Wherever They Exist
  • ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration
  • ASBv3-PA-6 Use privileged access workstations
  • DP-3 Encrypt sensitive data in transit

C5 (Germany) · 2 controls

  • C5-COS-05 Networks for administration
  • C5-CRY-02 Encryption of data for transmission (transport encryption)

FedRAMP High · 2 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • SC-8(1) Cryptographic Protection

FedRAMP Moderate · 2 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • SC-8(1) Cryptographic Protection

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 8.2 Privileged access rights
  • 8.24 Use of cryptography

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

ISO 27701:2019 · 1 control

  • 6.7.1 Cryptographic controls
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • P2-4.5.1 P2-4.5.1 VPNs into the 3DE securely configured

SOC 2 · 1 control

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 2: Secure Configurations

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 2.2.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 36 it maps to, and the evidence behind each claim, over MCP and REST.