4.2 PAN is protected with strong cryptography during transmission
How to meet it
Use strong TLS, accept only trusted keys/certificates, and maintain an inventory of where PAN is sent.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 4.2, in plain English.
4.2.1Strong cryptography and security protocols safeguard PAN in transit over open networks, accepting only trusted keys and valid certificates and using secure protocol versions.
4.2.1.1An up-to-date inventory of trusted keys and certificates used to protect PAN in transit is maintained.
4.2.1.2Wireless networks transmitting PAN or connected to the CDE use strong cryptography for authentication and transmission.
4.2.2PAN is protected with strong cryptography whenever sent via end-user messaging technologies.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Cryptography and key management policyUse for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Asset management policyUse for ISO 27001 A.5.9, A.5.10, A.5.11, A.7.9 to A.7.14, SOC 2 Security, and PCI DSS asset inventory expectations.Network security policyUse for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4.
Open the control-to-policy mapBack to Requirement 4, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.