← PCI DSS 4.0.1 · Req 6 — Secure systems and software

6.4.1-6.4.2 — Public-facing web applications are protected against attacks

high api-securitynetwork-security

Requirement

Public-facing web applications are protected against known attacks — for those in scope, by an automated technical solution such as a web application firewall that continually detects and prevents web-based attacks, is kept up to date, and generates alerts.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
web applicationweb applicationspublic-facingwebsiteweb appweb appscheckout
Required element 2 — any one of
wafweb application firewallautomated technical solutiondetects and preventsblocks attacks
Supporting terms — specificity signals
6.4.16.4.2owasprules updatedalerts

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 CC6.6 Boundary protection network-security
ISO 27001 A.8.21 Security of network services network-security
ISO 27001 A.8.22 Segregation of networks network-security
ISO 27001 A.8.28 Secure coding api-security
NIST CSF 2.0 PR.DS-02 Confidentiality, integrity and availability of data in transit network-security
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorised logical access network-security
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored network-security