Skip to content
Cyber Horizon
All frameworks

// Payment Security

PCI DSS 4.0 Compliance Software

Payment Card Industry Data Security Standard. Applies to all entities handling cardholder data.

Framework at a glance

Short name

PCI DSS

Version

4.0

Category

Payment Security

Controls

63

What PCI DSS covers

63 controls across 43 domains — every one tracked, owned and evidenced in Cyber Horizon.

Network Controls

4 controls
  • R1.1 Install and maintain network security controls
  • R1.2 Network security control configurations
  • R1.3 Network access to cardholder data environment
  • R1.4 Network connections between trusted and untrusted networks

Mobile Security

1 controls
  • R1.5 Risks to CDE from computing devices able to connect to untrusted networks

Configuration Management

1 controls
  • R2.1 Processes and mechanisms for applying secure configurations

Hardening

1 controls
  • R2.2 System components are configured and managed securely

Wireless

2 controls
  • R2.3 Wireless environments are configured and managed securely
  • R11.2 Wireless access points are identified and monitored

Data Storage

2 controls
  • R3.1 Processes for protection of stored account data
  • R3.3 Sensitive authentication data is not retained

Data Minimisation

1 controls
  • R3.2 Storage of account data is kept to a minimum

Cryptography

2 controls
  • R3.4 Primary account numbers (PAN) are secured
  • R3.5 Primary account number security when used electronically

Key Management

2 controls
  • R3.6 Cryptographic keys used to protect account data
  • R3.7 Key management policies and procedures

Encryption

2 controls
  • R4.1 Processes to protect cardholder data in transit
  • R4.2 PAN is protected with strong cryptography in transit

Malware

3 controls
  • R5.1 Processes to protect systems against malware
  • R5.2 Malware threats are addressed
  • R5.3 Anti-malware mechanisms and processes are active

Phishing

1 controls
  • R5.4 Anti-phishing mechanisms protect users

SDLC

1 controls
  • R6.1 Processes to develop and maintain secure systems

Coding

1 controls
  • R6.2 Bespoke and custom software are developed securely

Vulnerability Management

1 controls
  • R6.3 Security vulnerabilities are identified and addressed

Web Security

1 controls
  • R6.4 Public-facing web applications are protected

Change Management

1 controls
  • R6.5 Changes to system components are managed

Access Control

3 controls
  • R7.1 Processes to restrict access to system components
  • R7.2 Access to system components and data is appropriately defined
  • R7.3 Access to system components and data is managed

Identity Management

2 controls
  • R8.1 Processes to identify users and authenticate access
  • R8.2 User identification and related accounts are managed

Authentication

1 controls
  • R8.3 User authentication is managed

MFA

1 controls
  • R8.4 MFA is implemented for CDE access

Privileged Access

2 controls
  • R8.5 Application and system accounts are managed
  • R8.6 System/application accounts and authentication factors are managed

Physical Access

4 controls
  • R9.1 Processes to restrict physical access
  • R9.2 Physical access controls for facilities
  • R9.3 Physical access for personnel
  • R9.4 Physical access for visitors

POS Security

1 controls
  • R9.5 POS devices are protected

Logging

2 controls
  • R10.1 Processes for logging and monitoring
  • R10.2 Audit logs capture all applicable activities

Log Integrity

1 controls
  • R10.3 Audit logs are protected from destruction and modifications

Monitoring

1 controls
  • R10.4 Audit logs are reviewed

Retention

1 controls
  • R10.5 Audit log history is retained

Time Sync

1 controls
  • R10.6 Time synchronisation mechanisms

Incident Detection

1 controls
  • R10.7 Failures of security controls are detected

Testing

1 controls
  • R11.1 Processes to test security of systems

Vulnerability Scanning

1 controls
  • R11.3 External and internal vulnerabilities are regularly identified

Penetration Testing

1 controls
  • R11.4 External and internal penetration testing is regularly performed

Intrusion Detection

1 controls
  • R11.5 Network intrusions and unexpected file changes are detected

Web Monitoring

1 controls
  • R11.6 Web-facing applications are monitored

Policy

2 controls
  • R12.1 Information security policy is established
  • R12.2 Acceptable use policies for end-user technologies

Risk Management

1 controls
  • R12.3 Risks are identified and managed

Governance

1 controls
  • R12.4 PCI DSS compliance is managed

Scope Management

1 controls
  • R12.5 PCI DSS scope is documented

Training

1 controls
  • R12.6 Security awareness education is ongoing

HR Security

1 controls
  • R12.7 Personnel are screened

Third-Party

2 controls
  • R12.8 Risk to information from third-party relationships
  • R12.9 Third-party service providers support customer compliance

Incident Response

1 controls
  • R12.10 Suspected and confirmed security incidents are responded to

How Cyber Horizon automates PCI DSS

Every PCI DSS control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is PCI DSS 4.0?

Payment Card Industry Data Security Standard. Applies to all entities handling cardholder data.

How many controls does PCI DSS 4.0 have?

PCI DSS 4.0 (4.0) has 63 controls in Cyber Horizon's catalogue, organised across 43 domains.

How does Cyber Horizon help with PCI DSS 4.0?

Cyber Horizon maps PCI DSS 4.0 into a shared control library alongside every other framework you run, so evidence collected once counts towards PCI DSS and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See PCI DSS mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of PCI DSS in Cyber Horizon.