Public-facing web applications must have new threats and vulnerabilities handled continuously and the applications protected from known attacks using one of two methods. Option one: review the applications, using automated or manual tools or methods for assessing application vulnerability and security, at least every 12 months plus following any significant change, performed by an entity that specialises in application security, covering at minimum every common attack category listed in 6.2.4, with all vulnerabilities ranked per Requirement 6.3.1, all vulnerabilities corrected, and the application re-assessed after correction. Option two: install an automated technical control that constantly spots and stops web-based attacks, placed in front of the public-facing applications, actively running and updated as relevant, producing audit logs, and set either to block attacks or to raise an alert that is investigated immediately. It applies to all entities with public-facing web applications. Applicability: this is distinct from the internal and external scans (11.3.1, 11.3.2); 6.4.2 supersedes this requirement after 31 March 2025, when 6.4.2 becomes effective. Objective under the customized approach: public-facing web applications are defended against malicious attacks.
This control maps to 49 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
PCI DSS 4.0 6.4.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.
The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.