// Payment Security
PCI DSS 4.0 Compliance Software
Payment Card Industry Data Security Standard. Applies to all entities handling cardholder data.
Framework at a glance
Short name
PCI DSS
Version
4.0
Category
Payment Security
Controls
63
What PCI DSS covers
63 controls across 43 domains — every one tracked, owned and evidenced in Cyber Horizon.
Network Controls
4 controls- R1.1 Install and maintain network security controls
- R1.2 Network security control configurations
- R1.3 Network access to cardholder data environment
- R1.4 Network connections between trusted and untrusted networks
Mobile Security
1 controls- R1.5 Risks to CDE from computing devices able to connect to untrusted networks
Configuration Management
1 controls- R2.1 Processes and mechanisms for applying secure configurations
Hardening
1 controls- R2.2 System components are configured and managed securely
Wireless
2 controls- R2.3 Wireless environments are configured and managed securely
- R11.2 Wireless access points are identified and monitored
Data Storage
2 controls- R3.1 Processes for protection of stored account data
- R3.3 Sensitive authentication data is not retained
Data Minimisation
1 controls- R3.2 Storage of account data is kept to a minimum
Cryptography
2 controls- R3.4 Primary account numbers (PAN) are secured
- R3.5 Primary account number security when used electronically
Key Management
2 controls- R3.6 Cryptographic keys used to protect account data
- R3.7 Key management policies and procedures
Encryption
2 controls- R4.1 Processes to protect cardholder data in transit
- R4.2 PAN is protected with strong cryptography in transit
Malware
3 controls- R5.1 Processes to protect systems against malware
- R5.2 Malware threats are addressed
- R5.3 Anti-malware mechanisms and processes are active
Phishing
1 controls- R5.4 Anti-phishing mechanisms protect users
SDLC
1 controls- R6.1 Processes to develop and maintain secure systems
Coding
1 controls- R6.2 Bespoke and custom software are developed securely
Vulnerability Management
1 controls- R6.3 Security vulnerabilities are identified and addressed
Web Security
1 controls- R6.4 Public-facing web applications are protected
Change Management
1 controls- R6.5 Changes to system components are managed
Access Control
3 controls- R7.1 Processes to restrict access to system components
- R7.2 Access to system components and data is appropriately defined
- R7.3 Access to system components and data is managed
Identity Management
2 controls- R8.1 Processes to identify users and authenticate access
- R8.2 User identification and related accounts are managed
Authentication
1 controls- R8.3 User authentication is managed
MFA
1 controls- R8.4 MFA is implemented for CDE access
Privileged Access
2 controls- R8.5 Application and system accounts are managed
- R8.6 System/application accounts and authentication factors are managed
Physical Access
4 controls- R9.1 Processes to restrict physical access
- R9.2 Physical access controls for facilities
- R9.3 Physical access for personnel
- R9.4 Physical access for visitors
POS Security
1 controls- R9.5 POS devices are protected
Logging
2 controls- R10.1 Processes for logging and monitoring
- R10.2 Audit logs capture all applicable activities
Log Integrity
1 controls- R10.3 Audit logs are protected from destruction and modifications
Monitoring
1 controls- R10.4 Audit logs are reviewed
Retention
1 controls- R10.5 Audit log history is retained
Time Sync
1 controls- R10.6 Time synchronisation mechanisms
Incident Detection
1 controls- R10.7 Failures of security controls are detected
Testing
1 controls- R11.1 Processes to test security of systems
Vulnerability Scanning
1 controls- R11.3 External and internal vulnerabilities are regularly identified
Penetration Testing
1 controls- R11.4 External and internal penetration testing is regularly performed
Intrusion Detection
1 controls- R11.5 Network intrusions and unexpected file changes are detected
Web Monitoring
1 controls- R11.6 Web-facing applications are monitored
Policy
2 controls- R12.1 Information security policy is established
- R12.2 Acceptable use policies for end-user technologies
Risk Management
1 controls- R12.3 Risks are identified and managed
Governance
1 controls- R12.4 PCI DSS compliance is managed
Scope Management
1 controls- R12.5 PCI DSS scope is documented
Training
1 controls- R12.6 Security awareness education is ongoing
HR Security
1 controls- R12.7 Personnel are screened
Third-Party
2 controls- R12.8 Risk to information from third-party relationships
- R12.9 Third-party service providers support customer compliance
Incident Response
1 controls- R12.10 Suspected and confirmed security incidents are responded to
How Cyber Horizon automates PCI DSS
Every PCI DSS control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is PCI DSS 4.0?
Payment Card Industry Data Security Standard. Applies to all entities handling cardholder data.
How many controls does PCI DSS 4.0 have?
PCI DSS 4.0 (4.0) has 63 controls in Cyber Horizon's catalogue, organised across 43 domains.
How does Cyber Horizon help with PCI DSS 4.0?
Cyber Horizon maps PCI DSS 4.0 into a shared control library alongside every other framework you run, so evidence collected once counts towards PCI DSS and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
See PCI DSS mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of PCI DSS in Cyber Horizon.