💼 4.2.1 Strong cryptography and security protocols are implemented to safeguard PAN during transmission over open, public networks.
- ID:
/frameworks/pci-dss-v4.0.1/04/02/01
Stats
not available
Description
As following:
- Only trusted keys and certificates are accepted.
- Certificates used to safeguard PAN during transmission over open, public networks are confirmed as valid and are not expired or revoked. This bullet is a best practice until its effective date; refer to applicability notes below for details.
- The protocol in use supports only secure versions or configurations and does not support fallback to, or use of insecure versions, algorithms, key sizes, or implementations.
- The encryption strength is appropriate for the encryption methodology in use.
Similar
- Sections
/frameworks/pci-dss-v4.0/04/02/01/frameworks/aws-fsbp-v1.0.0/acm/01/frameworks/aws-fsbp-v1.0.0/acm/02/frameworks/aws-fsbp-v1.0.0/cloudfront/03/frameworks/aws-fsbp-v1.0.0/cloudfront/08/frameworks/aws-fsbp-v1.0.0/cloudfront/10/frameworks/aws-fsbp-v1.0.0/dms/09/frameworks/aws-fsbp-v1.0.0/dms/12/frameworks/aws-fsbp-v1.0.0/dynamodb/07/frameworks/aws-fsbp-v1.0.0/elasticache/05/frameworks/aws-fsbp-v1.0.0/elb/03/frameworks/aws-fsbp-v1.0.0/elb/08/frameworks/aws-fsbp-v1.0.0/es/03/frameworks/aws-fsbp-v1.0.0/es/08/frameworks/aws-fsbp-v1.0.0/msk/01/frameworks/aws-fsbp-v1.0.0/msk/03/frameworks/aws-fsbp-v1.0.0/redshift/02/frameworks/aws-fsbp-v1.0.0/s3/05/frameworks/aws-fsbp-v1.0.0/transfer-family/02
Similar Sections (Take Policies From)
Similar Sections (Give Policies To)
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 PCI DSS v4.0 → 💼 4.2.1 Strong cryptography and security protocols are implemented to safeguard PAN during transmission over open, public networks. | 2 | 9 | 28 | no data |
Sub Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 4.2.1.1 An inventory of the entity's trusted keys and certificates used to protect PAN during transmission is maintained. | no data | ||||
| 💼 4.2.1.2 Wireless networks transmitting PAN or connected to the CDE use industry best practices to implement strong cryptography for authentication and transmission. | 1 | no data |