Skip to main content

💼 1.4.1 NSCs are implemented between trusted and untrusted networks.

  • ID: /frameworks/pci-dss-v4.0/01/04/01

Description

Empty...

Similar

  • Sections
    • /frameworks/pci-dss-v3.2.1/01/03
    • /frameworks/pci-dss-v4.0.1/01/04/01
  • Internal
    • ID: dec-c-9f578ede

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 1.3 Prohibit direct public access between the Internet and any system component in the cardholder data environment.7844no data
💼 PCI DSS v4.0.1 → 💼 1.4.1 NSCs are implemented between trusted and untrusted networks.21no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 1.3 Prohibit direct public access between the Internet and any system component in the cardholder data environment.7844no data
💼 PCI DSS v4.0.1 → 💼 1.4.1 NSCs are implemented between trusted and untrusted networks.21no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (21)

PolicyLogic CountFlagsCompliance
🛡️ AWS DMS Replication Instance is publicly accessible🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted CIFS traffic🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted traffic to MongoDB🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted traffic to Oracle DBMS🟢1🟢 x6no data
🛡️ AWS RDS Instance is publicly accessible🟢1🟢 x6no data
🛡️ AWS RDS Snapshot is publicly accessible🟢1🟢 x6no data
🛡️ AWS S3 Bucket is not configured to block public access🟢1🟢 x6no data
🛡️ Azure Cosmos DB Account Private Endpoints are not used🟢1🟢 x6no data
🛡️ Azure Cosmos DB Account Virtual Network Filter is not enabled🟢1🟢 x6no data
🛡️ Azure Cosmos DB Entra ID Client Authentication is not used🟢⚪🟢 x2, ⚪ x1no data
🛡️ Azure Network Security Group allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to RDP port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to SSH port🟢1🟢 x6no data
🛡️ Azure SQL Database allows ingress from 0.0.0.0/0 (ANY IP)🟢1🟢 x6no data
🛡️ Azure Storage Account Allow Blob Anonymous Access is enabled🟢1🟢 x6no data
🛡️ Google GCE Instance IP Forwarding is not disabled.🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted SSH traffic🟢1🟢 x6no data
🛡️ Google GKE Cluster Network policy is disabled.🟢1🟢 x6no data
🛡️ Google GKE Cluster Private Google Access is not enabled.🟢1🟢 x6no data
🛡️ Oracle IAAS Security List allows unrestricted RDP traffic🟢1🟢 x6no data
🛡️ Oracle IAAS Security List allows unrestricted SSH traffic🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-14bf01f31
✉️ dec-x-46a83a301
✉️ dec-x-0289e9c91
✉️ dec-x-637372481
✉️ dec-x-afca7c621
✉️ dec-x-e02b5fdd1
✉️ dec-x-f4cc003a1
✉️ dec-x-fab5c4cd1
✉️ dec-z-c82c9f971