← PCI DSS 4.0.1 · Req 6 — Secure systems and software
6.4.3 — Payment page scripts are authorised, inventoried and integrity-checked
Requirement
Every script loaded and executed in the consumer's browser on payment pages is authorised, has its integrity assured (for example by SRI or a CSP), and is listed in an inventory with a written business or technical justification.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(1)(d) | Accuracy | integrity |
| GDPR | Art.16 | Right to rectification | integrity |
| CCPA/CPRA | 1798.106 | Right to correct | integrity |
| SOC 2 | PI1.1 | Quality information about processing objectives and specifications | integrity |
| ISO 27001 | A.8.25 | Secure development life cycle | secure-development |
| ISO 27001 | A.8.28 | Secure coding | secure-development |
| HIPAA | 164.312(c)(1) | Integrity (R/A) | integrity |
| GLBA | 314.4(c)(4) | Secure development and assessment of applications | secure-development |