-
Notifications
You must be signed in to change notification settings - Fork 706
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update PCI-DSS control file for version 4.0.1 #12435
Conversation
A new version was released on 2025-06 including some wording updates. No requirement was included, removed or technically changed. Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
Clarificatin about "a legitimate and documented business need." Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
The last bullet point was slightly updated. This commit also includes a formatting issue (no text change) in 6.4.1. Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
Clarify that the requirement is for all "non-console" access into the CDE. Signed-off-by: Marcus Burghardt <[email protected]>
Clarify that this requirement applies to "remote access" rather than the confusing term "remote network access". Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
Incremented to "high-risk vulnerabilities or critical vulnerabilities." Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
Intended for clarification. Signed-off-by: Marcus Burghardt <[email protected]>
Signed-off-by: Marcus Burghardt <[email protected]>
🤖 A k8s content image for this PR is available at: Click here to see how to deploy itIf you alread have Compliance Operator deployed: Otherwise deploy the content and operator together by checking out ComplianceAsCode/compliance-operator and: |
Code Climate has analyzed commit 1d4a11c and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 59.5% (0.0% change). View more on Code Climate. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks.
Description:
PCI-DSS released a new version of PCI-DSS policy in June-2024.
The changes are more about wording and clarification, without any technical impact on rules.
Rationale:
Review Hints:
My recommendation is to check the Summary of Changes document and the individual commits.
It is also helpful to open the two versions to compare the changes if the changelog is not enough to give more context.