Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 19 additions & 19 deletions data/backlinks.json
Original file line number Diff line number Diff line change
Expand Up @@ -34918,7 +34918,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 1.3",
"control_name": "Req 1.3",
"control_name": "Network access to and from the cardholder data environment is restricted.",
"entries": [
{
"id": "ASI08",
Expand Down Expand Up @@ -34968,7 +34968,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 10.2",
"control_name": "Req 10.2",
"control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.",
"entries": [
{
"id": "ASI01",
Expand Down Expand Up @@ -35223,7 +35223,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 10.7",
"control_name": "Req 10.7",
"control_name": "Failures of critical security control systems are detected, reported, and responded to promptly.",
"entries": [
{
"id": "ASI08",
Expand All @@ -35239,7 +35239,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 11.3",
"control_name": "Req 11.3",
"control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.",
"entries": [
{
"id": "ASI01",
Expand Down Expand Up @@ -35411,7 +35411,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 12.3",
"control_name": "Req 12.3",
"control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.",
"entries": [
{
"id": "ASI01",
Expand Down Expand Up @@ -35617,7 +35617,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 12.6",
"control_name": "Req 12.6",
"control_name": "Security awareness education is an ongoing activity.",
"entries": [
{
"id": "ASI09",
Expand Down Expand Up @@ -35803,7 +35803,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 2.2",
"control_name": "Req 2.2",
"control_name": "System components are configured and managed securely.",
"entries": [
{
"id": "ASI04",
Expand Down Expand Up @@ -35903,7 +35903,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 3.4",
"control_name": "Req 3.4",
"control_name": "Access to displays of full PAN and ability to copy PAN is restricted.",
"entries": [
{
"id": "ASI06",
Expand Down Expand Up @@ -35998,7 +35998,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 3.5",
"control_name": "Req 3.5",
"control_name": "Primary account number (PAN) is secured wherever it is stored.",
"entries": [
{
"id": "ASI06",
Expand Down Expand Up @@ -36102,7 +36102,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 4.2",
"control_name": "Req 4.2",
"control_name": "PAN is protected with strong cryptography during transmission.",
"entries": [
{
"id": "ASI07",
Expand Down Expand Up @@ -36152,7 +36152,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 5.2",
"control_name": "Req 5.2",
"control_name": "Malicious software (malware) is prevented, or detected and addressed.",
"entries": [
{
"id": "ASI04",
Expand Down Expand Up @@ -36281,7 +36281,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 6.3",
"control_name": "Req 6.3",
"control_name": "Security vulnerabilities are identified and addressed.",
"entries": [
{
"id": "ASI04",
Expand Down Expand Up @@ -36340,7 +36340,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 6.4",
"control_name": "Req 6.4",
"control_name": "Public-facing web applications are protected against attacks.",
"entries": [
{
"id": "ASI05",
Expand Down Expand Up @@ -36483,7 +36483,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 7.2",
"control_name": "Req 7.2",
"control_name": "Access to system components and data is appropriately defined and assigned.",
"entries": [
{
"id": "ASI02",
Expand Down Expand Up @@ -36650,7 +36650,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 7.3",
"control_name": "Req 7.3",
"control_name": "Access to system components and data is managed via an access control system(s).",
"entries": [
{
"id": "ASI02",
Expand Down Expand Up @@ -36682,7 +36682,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 8.2",
"control_name": "Req 8.2",
"control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.",
"entries": [
{
"id": "ASI03",
Expand Down Expand Up @@ -36723,7 +36723,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 8.3",
"control_name": "Req 8.3",
"control_name": "Strong authentication for users and administrators is established and managed.",
"entries": [
{
"id": "ASI03",
Expand Down Expand Up @@ -38295,7 +38295,7 @@
{
"framework": "SOC 2",
"control_id": "P7.1",
"control_name": "P7.1",
"control_name": "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.",
"entries": [
{
"id": "ASI09",
Expand Down Expand Up @@ -38415,7 +38415,7 @@
{
"framework": "SOC 2",
"control_id": "PI1.3",
"control_name": "PI1.3",
"control_name": "The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.",
"entries": [
{
"id": "ASI09",
Expand Down
6 changes: 3 additions & 3 deletions data/entries/ASI01.json
Original file line number Diff line number Diff line change
Expand Up @@ -532,7 +532,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 11.3",
"control_name": "Req 11.3",
"control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.",
"tier": "Foundational",
"scope": "Both",
"notes": "Pen test report with goal hijack test cases",
Expand All @@ -542,7 +542,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 10.2",
"control_name": "Req 10.2",
"control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.",
"tier": "Foundational",
"scope": "Both",
"notes": "Audit log configuration, sample log entries",
Expand All @@ -552,7 +552,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 12.3",
"control_name": "Req 12.3",
"control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.",
"tier": "Foundational",
"scope": "Both",
"notes": "Risk analysis for agentic AI in PCI scope",
Expand Down
6 changes: 3 additions & 3 deletions data/entries/ASI02.json
Original file line number Diff line number Diff line change
Expand Up @@ -512,7 +512,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 7.2",
"control_name": "Req 7.2",
"control_name": "Access to system components and data is appropriately defined and assigned.",
"tier": "Foundational",
"scope": "Both",
"notes": "Access control matrix for agent tools, privilege review records",
Expand All @@ -522,7 +522,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 7.3",
"control_name": "Req 7.3",
"control_name": "Access to system components and data is managed via an access control system(s).",
"tier": "Foundational",
"scope": "Both",
"notes": "Periodic access review records",
Expand All @@ -532,7 +532,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 10.2",
"control_name": "Req 10.2",
"control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.",
"tier": "Foundational",
"scope": "Both",
"notes": "Tool invocation audit log",
Expand Down
8 changes: 4 additions & 4 deletions data/entries/ASI03.json
Original file line number Diff line number Diff line change
Expand Up @@ -512,7 +512,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 8.2",
"control_name": "Req 8.2",
"control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.",
"tier": "Foundational",
"scope": "Both",
"notes": "Account inventory, unique account evidence",
Expand All @@ -522,7 +522,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 8.3",
"control_name": "Req 8.3",
"control_name": "Strong authentication for users and administrators is established and managed.",
"tier": "Foundational",
"scope": "Both",
"notes": "Credential management policy, rotation records",
Expand All @@ -532,7 +532,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 7.2",
"control_name": "Req 7.2",
"control_name": "Access to system components and data is appropriately defined and assigned.",
"tier": "Foundational",
"scope": "Both",
"notes": "Access control matrix, need-to-know justification",
Expand All @@ -542,7 +542,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 10.2",
"control_name": "Req 10.2",
"control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.",
"tier": "Foundational",
"scope": "Both",
"notes": "Authentication audit log",
Expand Down
6 changes: 3 additions & 3 deletions data/entries/ASI04.json
Original file line number Diff line number Diff line change
Expand Up @@ -523,7 +523,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 6.3",
"control_name": "Req 6.3",
"control_name": "Security vulnerabilities are identified and addressed.",
"tier": "Foundational",
"scope": "Both",
"notes": "Vulnerability scan results, patch records",
Expand All @@ -533,7 +533,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 5.2",
"control_name": "Req 5.2",
"control_name": "Malicious software (malware) is prevented, or detected and addressed.",
"tier": "Foundational",
"scope": "Both",
"notes": "Integrity check configuration, verification records",
Expand All @@ -543,7 +543,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 2.2",
"control_name": "Req 2.2",
"control_name": "System components are configured and managed securely.",
"tier": "Foundational",
"scope": "Both",
"notes": "Hardening baseline documentation",
Expand Down
6 changes: 3 additions & 3 deletions data/entries/ASI05.json
Original file line number Diff line number Diff line change
Expand Up @@ -512,7 +512,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 6.4",
"control_name": "Req 6.4",
"control_name": "Public-facing web applications are protected against attacks.",
"tier": "Hardening",
"scope": "Both",
"notes": "WAF configuration, protection evidence",
Expand All @@ -522,7 +522,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 11.3",
"control_name": "Req 11.3",
"control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.",
"tier": "Hardening",
"scope": "Both",
"notes": "Pen test report with code execution test cases",
Expand All @@ -532,7 +532,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 10.2",
"control_name": "Req 10.2",
"control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.",
"tier": "Hardening",
"scope": "Both",
"notes": "Code execution audit log",
Expand Down
6 changes: 3 additions & 3 deletions data/entries/ASI06.json
Original file line number Diff line number Diff line change
Expand Up @@ -502,7 +502,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 3.4",
"control_name": "Req 3.4",
"control_name": "Access to displays of full PAN and ability to copy PAN is restricted.",
"tier": "Hardening",
"scope": "Both",
"notes": "Memory store review, PAN protection evidence",
Expand All @@ -512,7 +512,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 3.5",
"control_name": "Req 3.5",
"control_name": "Primary account number (PAN) is secured wherever it is stored.",
"tier": "Hardening",
"scope": "Both",
"notes": "Encryption configuration, key management records",
Expand All @@ -532,7 +532,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 11.3",
"control_name": "Req 11.3",
"control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.",
"tier": "Hardening",
"scope": "Both",
"notes": "Pen test report",
Expand Down
6 changes: 3 additions & 3 deletions data/entries/ASI07.json
Original file line number Diff line number Diff line change
Expand Up @@ -502,7 +502,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 4.2",
"control_name": "Req 4.2",
"control_name": "PAN is protected with strong cryptography during transmission.",
"tier": "Hardening",
"scope": "Both",
"notes": "TLS configuration, protocol verification",
Expand All @@ -512,7 +512,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 8.2",
"control_name": "Req 8.2",
"control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.",
"tier": "Hardening",
"scope": "Both",
"notes": "Certificate configuration, authentication evidence",
Expand All @@ -522,7 +522,7 @@
{
"framework": "PCI DSS v4.0",
"control_id": "Req 10.2",
"control_name": "Req 10.2",
"control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.",
"tier": "Hardening",
"scope": "Both",
"notes": "Inter-agent communication audit log",
Expand Down
Loading
Loading