Requirement 6 · Develop and maintain secure systems and software

6.4 Public-facing web applications are protected against attacks

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL6.4 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Use a WAF or regular automated/manual application reviews.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 6.4, in plain English.

6.4.1Public-facing web applications are protected against known attacks by recurring assessment or an automated technical solution.
6.4.2An automated technical solution is deployed in front of public-facing web applications to continually detect and prevent web-based attacks.
6.4.3All payment-page scripts in the consumer browser are authorized, integrity-checked, and inventoried with written justification.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 6, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.