6.4 Public-facing web applications are protected against attacks
How to meet it
Use a WAF or regular automated/manual application reviews.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 6.4, in plain English.
6.4.1Public-facing web applications are protected against known attacks by recurring assessment or an automated technical solution.
6.4.2An automated technical solution is deployed in front of public-facing web applications to continually detect and prevent web-based attacks.
6.4.3All payment-page scripts in the consumer browser are authorized, integrity-checked, and inventoried with written justification.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Secure development policyUse for ISO 27001 A.8.25 to A.8.32, source code controls, change management, and SOC 2 change controls.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.
Open the control-to-policy map← 6.3 Security vulnerabilities are identified and addressed6.5 Changes to all system components are managed securely →
Back to Requirement 6, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.