Skip to content

NIST 800-171PCI DSS crosswalk

A control-by-control mapping between NIST SP 800-171 Rev. 2 and PCI DSS v4.0. 7 mappings.

NIST 800-171PCI DSSRelationshipNotes
3.1.1
Limit system access to authorized users
Req. 7
Restrict access by business need to know
EquivalentCurated
Contrôle d'accès et identité
3.1.1
Limit system access to authorized users
Req. 8
Identify users and authenticate access
EquivalentCurated
Contrôle d'accès et identité
3.11.2
Scan for vulnerabilities
Req. 11
Test security of systems and networks regularly
EquivalentCurated
Gestion des vulnérabilités
3.13.11
Employ FIPS-validated cryptography
Req. 3
Protect stored account data
EquivalentCurated
Cryptographie et protection des données
3.13.11
Employ FIPS-validated cryptography
Req. 4
Protect cardholder data with strong cryptography during transmission
EquivalentCurated
Cryptographie et protection des données
3.3.1
Create and retain audit logs
Req. 10
Log and monitor all access to system components and cardholder data
EquivalentCurated
Journalisation, surveillance et détection
3.4.2
Establish and enforce security configuration settings
Req. 2
Apply secure configurations to all system components
EquivalentCurated
Configuration sécurisée et durcissement

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.