Skip to content

ISO 27001PCI DSS crosswalk

A control-by-control mapping between ISO/IEC 27001:2022 and PCI DSS v4.0. 8 mappings.

ISO 27001PCI DSSRelationshipNotes
A.5.1
Policies for information security
Req. 12
Support information security with organizational policies and programs
RelatedCurated
Governance & security policy
A.5.15
Access control
Req. 7
Restrict access by business need to know
EquivalentCurated
Access control & identity
A.5.15
Access control
Req. 8
Identify users and authenticate access
EquivalentCurated
Access control & identity
A.8.16
Monitoring activities
Req. 10
Log and monitor all access to system components and cardholder data
EquivalentCurated
Logging, monitoring & detection
A.8.24
Use of cryptography
Req. 3
Protect stored account data
EquivalentCurated
Cryptography & data protection
A.8.24
Use of cryptography
Req. 4
Protect cardholder data with strong cryptography during transmission
EquivalentCurated
Cryptography & data protection
A.8.8
Management of technical vulnerabilities
Req. 11
Test security of systems and networks regularly
EquivalentCurated
Vulnerability management
A.8.9
Configuration management
Req. 2
Apply secure configurations to all system components
EquivalentCurated
Secure configuration & hardening

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.