1.5 Risks from devices connecting to both untrusted networks and the CDE are mitigated
How to meet it
Harden laptops/endpoints that can reach the CDE (e.g. host firewalls, restrictions).
Defined requirements
The individual PCI DSS v4.0.1 requirements under 1.5, in plain English.
1.5.1Computing devices that connect to both untrusted networks and the CDE run enforced, non-user-alterable controls to stop threats entering the network.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Network security policyUse for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4.Malware protection policyUse for ISO 27001 A.8.7, SOC 2 Security, and PCI DSS requirement 5 anti-malware controls.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Endpoint and mobile device policyUse for ISO 27001 A.6.7, A.7.9, A.8.1, malware protection, remote work, and SOC 2 endpoint controls.
Open the control-to-policy mapBack to Requirement 1, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.