diff --git a/data/backlinks.json b/data/backlinks.json index 897fde5..f87b6f1 100644 --- a/data/backlinks.json +++ b/data/backlinks.json @@ -34918,7 +34918,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 1.3", - "control_name": "Req 1.3", + "control_name": "Network access to and from the cardholder data environment is restricted.", "entries": [ { "id": "ASI08", @@ -34968,7 +34968,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "entries": [ { "id": "ASI01", @@ -35223,7 +35223,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.7", - "control_name": "Req 10.7", + "control_name": "Failures of critical security control systems are detected, reported, and responded to promptly.", "entries": [ { "id": "ASI08", @@ -35239,7 +35239,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "entries": [ { "id": "ASI01", @@ -35411,7 +35411,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "entries": [ { "id": "ASI01", @@ -35617,7 +35617,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 12.6", - "control_name": "Req 12.6", + "control_name": "Security awareness education is an ongoing activity.", "entries": [ { "id": "ASI09", @@ -35803,7 +35803,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 2.2", - "control_name": "Req 2.2", + "control_name": "System components are configured and managed securely.", "entries": [ { "id": "ASI04", @@ -35903,7 +35903,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 3.4", - "control_name": "Req 3.4", + "control_name": "Access to displays of full PAN and ability to copy PAN is restricted.", "entries": [ { "id": "ASI06", @@ -35998,7 +35998,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 3.5", - "control_name": "Req 3.5", + "control_name": "Primary account number (PAN) is secured wherever it is stored.", "entries": [ { "id": "ASI06", @@ -36102,7 +36102,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 4.2", - "control_name": "Req 4.2", + "control_name": "PAN is protected with strong cryptography during transmission.", "entries": [ { "id": "ASI07", @@ -36152,7 +36152,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 5.2", - "control_name": "Req 5.2", + "control_name": "Malicious software (malware) is prevented, or detected and addressed.", "entries": [ { "id": "ASI04", @@ -36281,7 +36281,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 6.3", - "control_name": "Req 6.3", + "control_name": "Security vulnerabilities are identified and addressed.", "entries": [ { "id": "ASI04", @@ -36340,7 +36340,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 6.4", - "control_name": "Req 6.4", + "control_name": "Public-facing web applications are protected against attacks.", "entries": [ { "id": "ASI05", @@ -36483,7 +36483,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "entries": [ { "id": "ASI02", @@ -36650,7 +36650,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 7.3", - "control_name": "Req 7.3", + "control_name": "Access to system components and data is managed via an access control system(s).", "entries": [ { "id": "ASI02", @@ -36682,7 +36682,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 8.2", - "control_name": "Req 8.2", + "control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "entries": [ { "id": "ASI03", @@ -36723,7 +36723,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 8.3", - "control_name": "Req 8.3", + "control_name": "Strong authentication for users and administrators is established and managed.", "entries": [ { "id": "ASI03", @@ -38295,7 +38295,7 @@ { "framework": "SOC 2", "control_id": "P7.1", - "control_name": "P7.1", + "control_name": "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.", "entries": [ { "id": "ASI09", @@ -38415,7 +38415,7 @@ { "framework": "SOC 2", "control_id": "PI1.3", - "control_name": "PI1.3", + "control_name": "The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.", "entries": [ { "id": "ASI09", diff --git a/data/entries/ASI01.json b/data/entries/ASI01.json index a456b63..2028810 100644 --- a/data/entries/ASI01.json +++ b/data/entries/ASI01.json @@ -532,7 +532,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Foundational", "scope": "Both", "notes": "Pen test report with goal hijack test cases", @@ -542,7 +542,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Audit log configuration, sample log entries", @@ -552,7 +552,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Foundational", "scope": "Both", "notes": "Risk analysis for agentic AI in PCI scope", diff --git a/data/entries/ASI02.json b/data/entries/ASI02.json index 53b35f9..4680dc4 100644 --- a/data/entries/ASI02.json +++ b/data/entries/ASI02.json @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "tier": "Foundational", "scope": "Both", "notes": "Access control matrix for agent tools, privilege review records", @@ -522,7 +522,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 7.3", - "control_name": "Req 7.3", + "control_name": "Access to system components and data is managed via an access control system(s).", "tier": "Foundational", "scope": "Both", "notes": "Periodic access review records", @@ -532,7 +532,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Tool invocation audit log", diff --git a/data/entries/ASI03.json b/data/entries/ASI03.json index a9d1f3a..726ffae 100644 --- a/data/entries/ASI03.json +++ b/data/entries/ASI03.json @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 8.2", - "control_name": "Req 8.2", + "control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "tier": "Foundational", "scope": "Both", "notes": "Account inventory, unique account evidence", @@ -522,7 +522,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 8.3", - "control_name": "Req 8.3", + "control_name": "Strong authentication for users and administrators is established and managed.", "tier": "Foundational", "scope": "Both", "notes": "Credential management policy, rotation records", @@ -532,7 +532,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "tier": "Foundational", "scope": "Both", "notes": "Access control matrix, need-to-know justification", @@ -542,7 +542,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Authentication audit log", diff --git a/data/entries/ASI04.json b/data/entries/ASI04.json index 19e6fad..97e4c7a 100644 --- a/data/entries/ASI04.json +++ b/data/entries/ASI04.json @@ -523,7 +523,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 6.3", - "control_name": "Req 6.3", + "control_name": "Security vulnerabilities are identified and addressed.", "tier": "Foundational", "scope": "Both", "notes": "Vulnerability scan results, patch records", @@ -533,7 +533,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 5.2", - "control_name": "Req 5.2", + "control_name": "Malicious software (malware) is prevented, or detected and addressed.", "tier": "Foundational", "scope": "Both", "notes": "Integrity check configuration, verification records", @@ -543,7 +543,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 2.2", - "control_name": "Req 2.2", + "control_name": "System components are configured and managed securely.", "tier": "Foundational", "scope": "Both", "notes": "Hardening baseline documentation", diff --git a/data/entries/ASI05.json b/data/entries/ASI05.json index 6498a58..ee9f6ef 100644 --- a/data/entries/ASI05.json +++ b/data/entries/ASI05.json @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 6.4", - "control_name": "Req 6.4", + "control_name": "Public-facing web applications are protected against attacks.", "tier": "Hardening", "scope": "Both", "notes": "WAF configuration, protection evidence", @@ -522,7 +522,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Hardening", "scope": "Both", "notes": "Pen test report with code execution test cases", @@ -532,7 +532,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Hardening", "scope": "Both", "notes": "Code execution audit log", diff --git a/data/entries/ASI06.json b/data/entries/ASI06.json index b219647..268297a 100644 --- a/data/entries/ASI06.json +++ b/data/entries/ASI06.json @@ -502,7 +502,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 3.4", - "control_name": "Req 3.4", + "control_name": "Access to displays of full PAN and ability to copy PAN is restricted.", "tier": "Hardening", "scope": "Both", "notes": "Memory store review, PAN protection evidence", @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 3.5", - "control_name": "Req 3.5", + "control_name": "Primary account number (PAN) is secured wherever it is stored.", "tier": "Hardening", "scope": "Both", "notes": "Encryption configuration, key management records", @@ -532,7 +532,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Hardening", "scope": "Both", "notes": "Pen test report", diff --git a/data/entries/ASI07.json b/data/entries/ASI07.json index 7a415a2..c112955 100644 --- a/data/entries/ASI07.json +++ b/data/entries/ASI07.json @@ -502,7 +502,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 4.2", - "control_name": "Req 4.2", + "control_name": "PAN is protected with strong cryptography during transmission.", "tier": "Hardening", "scope": "Both", "notes": "TLS configuration, protocol verification", @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 8.2", - "control_name": "Req 8.2", + "control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "tier": "Hardening", "scope": "Both", "notes": "Certificate configuration, authentication evidence", @@ -522,7 +522,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Hardening", "scope": "Both", "notes": "Inter-agent communication audit log", diff --git a/data/entries/ASI08.json b/data/entries/ASI08.json index 4743572..310a894 100644 --- a/data/entries/ASI08.json +++ b/data/entries/ASI08.json @@ -502,7 +502,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.7", - "control_name": "Req 10.7", + "control_name": "Failures of critical security control systems are detected, reported, and responded to promptly.", "tier": "Foundational", "scope": "Both", "notes": "Monitoring configuration, alert records, detection evidence", @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Foundational", "scope": "Both", "notes": "Risk analysis documentation", @@ -522,7 +522,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 1.3", - "control_name": "Req 1.3", + "control_name": "Network access to and from the cardholder data environment is restricted.", "tier": "Foundational", "scope": "Both", "notes": "Network diagram, segmentation evidence", @@ -532,7 +532,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 2.2", - "control_name": "Req 2.2", + "control_name": "System components are configured and managed securely.", "tier": "Foundational", "scope": "Both", "notes": "Hardening baseline documentation", diff --git a/data/entries/ASI09.json b/data/entries/ASI09.json index 4eb1cca..4bbc9d3 100644 --- a/data/entries/ASI09.json +++ b/data/entries/ASI09.json @@ -472,7 +472,7 @@ { "framework": "SOC 2", "control_id": "PI1.3", - "control_name": "PI1.3", + "control_name": "The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.", "tier": "Foundational", "scope": "Both", "notes": "Output quality controls, factual accuracy testing", @@ -482,7 +482,7 @@ { "framework": "SOC 2", "control_id": "P7.1", - "control_name": "P7.1", + "control_name": "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.", "tier": "Foundational", "scope": "Both", "notes": "Accuracy review procedures", @@ -492,7 +492,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 12.6", - "control_name": "Req 12.6", + "control_name": "Security awareness education is an ongoing activity.", "tier": "Foundational", "scope": "Both", "notes": "Training curriculum, completion records", @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Interaction audit log", @@ -522,7 +522,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Foundational", "scope": "Both", "notes": "Risk analysis documentation", diff --git a/data/entries/ASI10.json b/data/entries/ASI10.json index 334f991..e037a42 100644 --- a/data/entries/ASI10.json +++ b/data/entries/ASI10.json @@ -512,7 +512,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "tier": "Hardening", "scope": "Both", "notes": "Access control matrix, technical enforcement evidence", @@ -522,7 +522,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Hardening", "scope": "Both", "notes": "Action audit log, out-of-scope alert records", @@ -532,7 +532,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Hardening", "scope": "Both", "notes": "Pen test report with rogue agent test cases", @@ -542,7 +542,7 @@ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Hardening", "scope": "Both", "notes": "Risk analysis documentation", diff --git a/data/frameworks/pci-dss.json b/data/frameworks/pci-dss.json index 151e924..a0e3e82 100644 --- a/data/frameworks/pci-dss.json +++ b/data/frameworks/pci-dss.json @@ -12,7 +12,7 @@ "controls": [ { "control_id": "Req 1.3", - "title": "Req 1.3", + "title": "Network access to and from the cardholder data environment is restricted.", "description": "Network diagram, segmentation evidence", "kind": "control", "parent": null @@ -25,7 +25,7 @@ }, { "control_id": "Req 2.2", - "title": "Req 2.2", + "title": "System components are configured and managed securely.", "description": "Hardening baseline documentation", "kind": "control", "parent": null @@ -50,7 +50,7 @@ }, { "control_id": "Req 3.4", - "title": "Req 3.4", + "title": "Access to displays of full PAN and ability to copy PAN is restricted.", "description": "Memory store review, PAN protection evidence", "kind": "control", "parent": null @@ -63,7 +63,7 @@ }, { "control_id": "Req 3.5", - "title": "Req 3.5", + "title": "Primary account number (PAN) is secured wherever it is stored.", "description": "Encryption configuration, key management records", "kind": "control", "parent": null @@ -76,7 +76,7 @@ }, { "control_id": "Req 4.2", - "title": "Req 4.2", + "title": "PAN is protected with strong cryptography during transmission.", "description": "TLS configuration, protocol verification", "kind": "control", "parent": null @@ -89,7 +89,7 @@ }, { "control_id": "Req 5.2", - "title": "Req 5.2", + "title": "Malicious software (malware) is prevented, or detected and addressed.", "description": "Integrity check configuration, verification records", "kind": "control", "parent": null @@ -108,7 +108,7 @@ }, { "control_id": "Req 6.3", - "title": "Req 6.3", + "title": "Security vulnerabilities are identified and addressed.", "description": "Vulnerability scan results, patch records", "kind": "control", "parent": null @@ -121,7 +121,7 @@ }, { "control_id": "Req 6.4", - "title": "Req 6.4", + "title": "Public-facing web applications are protected against attacks.", "description": "WAF configuration, protection evidence", "kind": "control", "parent": null @@ -152,7 +152,7 @@ }, { "control_id": "Req 7.2", - "title": "Req 7.2", + "title": "Access to system components and data is appropriately defined and assigned.", "description": "Access control matrix for agent tools, privilege review records", "kind": "control", "parent": null @@ -165,7 +165,7 @@ }, { "control_id": "Req 7.3", - "title": "Req 7.3", + "title": "Access to system components and data is managed via an access control system(s).", "description": "Periodic access review records", "kind": "control", "parent": null @@ -178,7 +178,7 @@ }, { "control_id": "Req 8.2", - "title": "Req 8.2", + "title": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "description": "Account inventory, unique account evidence", "kind": "control", "parent": null @@ -191,7 +191,7 @@ }, { "control_id": "Req 8.3", - "title": "Req 8.3", + "title": "Strong authentication for users and administrators is established and managed.", "description": "Credential management policy, rotation records", "kind": "control", "parent": null @@ -204,7 +204,7 @@ }, { "control_id": "Req 10.2", - "title": "Req 10.2", + "title": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "description": "Audit log configuration, sample log entries", "kind": "control", "parent": null @@ -223,14 +223,14 @@ }, { "control_id": "Req 10.7", - "title": "Req 10.7", + "title": "Failures of critical security control systems are detected, reported, and responded to promptly.", "description": "Monitoring configuration, alert records, detection evidence", "kind": "control", "parent": null }, { "control_id": "Req 11.3", - "title": "Req 11.3", + "title": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "description": "Pen test report with goal hijack test cases", "kind": "control", "parent": null @@ -249,7 +249,7 @@ }, { "control_id": "Req 12.3", - "title": "Req 12.3", + "title": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "description": "Risk analysis for agentic AI in PCI scope", "kind": "control", "parent": null @@ -280,7 +280,7 @@ }, { "control_id": "Req 12.6", - "title": "Req 12.6", + "title": "Security awareness education is an ongoing activity.", "description": "Training curriculum, completion records", "kind": "control", "parent": null @@ -334,6 +334,11 @@ "date": "2026-09-18", "change": "Migrated off the swapped-column ids of issue #35: 72 items -> 49", "author": "OWASP GenAI Data Security Initiative" + }, + { + "date": "2026-09-18", + "change": "Titled 17 entries that had carried only their identifier, from the published text: PCI DSS v4.0 requirement headings, transcribed from PCI SSC \"PCI DSS v4.0 SAQ D for Merchants\" — Req 1.3, Req 2.2, Req 3.4, Req 3.5, Req 4.2, Req 5.2, Req 6.3, Req 6.4, Req 7.2, Req 7.3, Req 8.2, Req 8.3, Req 10.2, Req 10.7, Req 11.3, Req 12.3, Req 12.6", + "author": "OWASP GenAI Data Security Initiative" } ] } diff --git a/data/frameworks/soc2.json b/data/frameworks/soc2.json index 1a5ae87..6b2c4ac 100644 --- a/data/frameworks/soc2.json +++ b/data/frameworks/soc2.json @@ -342,7 +342,7 @@ }, { "control_id": "P7.1", - "title": "P7.1", + "title": "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.", "description": "Accuracy review procedures", "kind": "control", "parent": null @@ -365,7 +365,7 @@ }, { "control_id": "PI1.3", - "title": "PI1.3", + "title": "The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.", "description": "Output quality controls, factual accuracy testing", "kind": "control", "parent": null @@ -381,6 +381,11 @@ "date": "2026-09-18", "change": "Migrated off the swapped-column ids of issue #35: 209 items -> 46", "author": "OWASP GenAI Data Security Initiative" + }, + { + "date": "2026-09-18", + "change": "Titled 2 entries that had carried only their identifier, from the published text: TSP section 100, 2017 Trust Services Criteria (with Revised Points of Focus — 2022) — P7.1, PI1.3", + "author": "OWASP GenAI Data Security Initiative" } ], "inventory_completeness": { diff --git a/docs/backlinks.js b/docs/backlinks.js index 04d8c80..4209206 100644 --- a/docs/backlinks.js +++ b/docs/backlinks.js @@ -34920,7 +34920,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 1.3", - "control_name": "Req 1.3", + "control_name": "Network access to and from the cardholder data environment is restricted.", "entries": [ { "id": "ASI08", @@ -34970,7 +34970,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "entries": [ { "id": "ASI01", @@ -35225,7 +35225,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.7", - "control_name": "Req 10.7", + "control_name": "Failures of critical security control systems are detected, reported, and responded to promptly.", "entries": [ { "id": "ASI08", @@ -35241,7 +35241,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "entries": [ { "id": "ASI01", @@ -35413,7 +35413,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "entries": [ { "id": "ASI01", @@ -35619,7 +35619,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 12.6", - "control_name": "Req 12.6", + "control_name": "Security awareness education is an ongoing activity.", "entries": [ { "id": "ASI09", @@ -35805,7 +35805,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 2.2", - "control_name": "Req 2.2", + "control_name": "System components are configured and managed securely.", "entries": [ { "id": "ASI04", @@ -35905,7 +35905,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 3.4", - "control_name": "Req 3.4", + "control_name": "Access to displays of full PAN and ability to copy PAN is restricted.", "entries": [ { "id": "ASI06", @@ -36000,7 +36000,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 3.5", - "control_name": "Req 3.5", + "control_name": "Primary account number (PAN) is secured wherever it is stored.", "entries": [ { "id": "ASI06", @@ -36104,7 +36104,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 4.2", - "control_name": "Req 4.2", + "control_name": "PAN is protected with strong cryptography during transmission.", "entries": [ { "id": "ASI07", @@ -36154,7 +36154,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 5.2", - "control_name": "Req 5.2", + "control_name": "Malicious software (malware) is prevented, or detected and addressed.", "entries": [ { "id": "ASI04", @@ -36283,7 +36283,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 6.3", - "control_name": "Req 6.3", + "control_name": "Security vulnerabilities are identified and addressed.", "entries": [ { "id": "ASI04", @@ -36342,7 +36342,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 6.4", - "control_name": "Req 6.4", + "control_name": "Public-facing web applications are protected against attacks.", "entries": [ { "id": "ASI05", @@ -36485,7 +36485,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "entries": [ { "id": "ASI02", @@ -36652,7 +36652,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 7.3", - "control_name": "Req 7.3", + "control_name": "Access to system components and data is managed via an access control system(s).", "entries": [ { "id": "ASI02", @@ -36684,7 +36684,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 8.2", - "control_name": "Req 8.2", + "control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "entries": [ { "id": "ASI03", @@ -36725,7 +36725,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "PCI DSS v4.0", "control_id": "Req 8.3", - "control_name": "Req 8.3", + "control_name": "Strong authentication for users and administrators is established and managed.", "entries": [ { "id": "ASI03", @@ -38297,7 +38297,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "SOC 2", "control_id": "P7.1", - "control_name": "P7.1", + "control_name": "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.", "entries": [ { "id": "ASI09", @@ -38417,7 +38417,7 @@ window.CROSSWALK_BACKLINKS = [ { "framework": "SOC 2", "control_id": "PI1.3", - "control_name": "PI1.3", + "control_name": "The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.", "entries": [ { "id": "ASI09", diff --git a/docs/data.js b/docs/data.js index e265859..3d58538 100644 --- a/docs/data.js +++ b/docs/data.js @@ -13344,7 +13344,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Foundational", "scope": "Both", "notes": "Pen test report with goal hijack test cases", @@ -13354,7 +13354,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Audit log configuration, sample log entries", @@ -13364,7 +13364,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Foundational", "scope": "Both", "notes": "Risk analysis for agentic AI in PCI scope", @@ -14675,7 +14675,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "tier": "Foundational", "scope": "Both", "notes": "Access control matrix for agent tools, privilege review records", @@ -14685,7 +14685,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 7.3", - "control_name": "Req 7.3", + "control_name": "Access to system components and data is managed via an access control system(s).", "tier": "Foundational", "scope": "Both", "notes": "Periodic access review records", @@ -14695,7 +14695,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Tool invocation audit log", @@ -15949,7 +15949,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 8.2", - "control_name": "Req 8.2", + "control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "tier": "Foundational", "scope": "Both", "notes": "Account inventory, unique account evidence", @@ -15959,7 +15959,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 8.3", - "control_name": "Req 8.3", + "control_name": "Strong authentication for users and administrators is established and managed.", "tier": "Foundational", "scope": "Both", "notes": "Credential management policy, rotation records", @@ -15969,7 +15969,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "tier": "Foundational", "scope": "Both", "notes": "Access control matrix, need-to-know justification", @@ -15979,7 +15979,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Authentication audit log", @@ -17291,7 +17291,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 6.3", - "control_name": "Req 6.3", + "control_name": "Security vulnerabilities are identified and addressed.", "tier": "Foundational", "scope": "Both", "notes": "Vulnerability scan results, patch records", @@ -17301,7 +17301,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 5.2", - "control_name": "Req 5.2", + "control_name": "Malicious software (malware) is prevented, or detected and addressed.", "tier": "Foundational", "scope": "Both", "notes": "Integrity check configuration, verification records", @@ -17311,7 +17311,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 2.2", - "control_name": "Req 2.2", + "control_name": "System components are configured and managed securely.", "tier": "Foundational", "scope": "Both", "notes": "Hardening baseline documentation", @@ -18478,7 +18478,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 6.4", - "control_name": "Req 6.4", + "control_name": "Public-facing web applications are protected against attacks.", "tier": "Hardening", "scope": "Both", "notes": "WAF configuration, protection evidence", @@ -18488,7 +18488,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Hardening", "scope": "Both", "notes": "Pen test report with code execution test cases", @@ -18498,7 +18498,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Hardening", "scope": "Both", "notes": "Code execution audit log", @@ -19660,7 +19660,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 3.4", - "control_name": "Req 3.4", + "control_name": "Access to displays of full PAN and ability to copy PAN is restricted.", "tier": "Hardening", "scope": "Both", "notes": "Memory store review, PAN protection evidence", @@ -19670,7 +19670,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 3.5", - "control_name": "Req 3.5", + "control_name": "Primary account number (PAN) is secured wherever it is stored.", "tier": "Hardening", "scope": "Both", "notes": "Encryption configuration, key management records", @@ -19690,7 +19690,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Hardening", "scope": "Both", "notes": "Pen test report", @@ -20831,7 +20831,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 4.2", - "control_name": "Req 4.2", + "control_name": "PAN is protected with strong cryptography during transmission.", "tier": "Hardening", "scope": "Both", "notes": "TLS configuration, protocol verification", @@ -20841,7 +20841,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 8.2", - "control_name": "Req 8.2", + "control_name": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "tier": "Hardening", "scope": "Both", "notes": "Certificate configuration, authentication evidence", @@ -20851,7 +20851,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Hardening", "scope": "Both", "notes": "Inter-agent communication audit log", @@ -21962,7 +21962,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.7", - "control_name": "Req 10.7", + "control_name": "Failures of critical security control systems are detected, reported, and responded to promptly.", "tier": "Foundational", "scope": "Both", "notes": "Monitoring configuration, alert records, detection evidence", @@ -21972,7 +21972,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Foundational", "scope": "Both", "notes": "Risk analysis documentation", @@ -21982,7 +21982,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 1.3", - "control_name": "Req 1.3", + "control_name": "Network access to and from the cardholder data environment is restricted.", "tier": "Foundational", "scope": "Both", "notes": "Network diagram, segmentation evidence", @@ -21992,7 +21992,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 2.2", - "control_name": "Req 2.2", + "control_name": "System components are configured and managed securely.", "tier": "Foundational", "scope": "Both", "notes": "Hardening baseline documentation", @@ -23062,7 +23062,7 @@ window.CROSSWALK_DATA = [ { "framework": "SOC 2", "control_id": "PI1.3", - "control_name": "PI1.3", + "control_name": "The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.", "tier": "Foundational", "scope": "Both", "notes": "Output quality controls, factual accuracy testing", @@ -23072,7 +23072,7 @@ window.CROSSWALK_DATA = [ { "framework": "SOC 2", "control_id": "P7.1", - "control_name": "P7.1", + "control_name": "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.", "tier": "Foundational", "scope": "Both", "notes": "Accuracy review procedures", @@ -23082,7 +23082,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 12.6", - "control_name": "Req 12.6", + "control_name": "Security awareness education is an ongoing activity.", "tier": "Foundational", "scope": "Both", "notes": "Training curriculum, completion records", @@ -23102,7 +23102,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Foundational", "scope": "Both", "notes": "Interaction audit log", @@ -23112,7 +23112,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Foundational", "scope": "Both", "notes": "Risk analysis documentation", @@ -24251,7 +24251,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 7.2", - "control_name": "Req 7.2", + "control_name": "Access to system components and data is appropriately defined and assigned.", "tier": "Hardening", "scope": "Both", "notes": "Access control matrix, technical enforcement evidence", @@ -24261,7 +24261,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 10.2", - "control_name": "Req 10.2", + "control_name": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "tier": "Hardening", "scope": "Both", "notes": "Action audit log, out-of-scope alert records", @@ -24271,7 +24271,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 11.3", - "control_name": "Req 11.3", + "control_name": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "tier": "Hardening", "scope": "Both", "notes": "Pen test report with rogue agent test cases", @@ -24281,7 +24281,7 @@ window.CROSSWALK_DATA = [ { "framework": "PCI DSS v4.0", "control_id": "Req 12.3", - "control_name": "Req 12.3", + "control_name": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "tier": "Hardening", "scope": "Both", "notes": "Risk analysis documentation", diff --git a/docs/frameworks-registry.js b/docs/frameworks-registry.js index f236bd8..06d6880 100644 --- a/docs/frameworks-registry.js +++ b/docs/frameworks-registry.js @@ -8406,7 +8406,7 @@ window.CROSSWALK_FRAMEWORKS = [ "controls": [ { "control_id": "Req 1.3", - "title": "Req 1.3", + "title": "Network access to and from the cardholder data environment is restricted.", "description": "Network diagram, segmentation evidence", "kind": "control", "parent": null @@ -8419,7 +8419,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 2.2", - "title": "Req 2.2", + "title": "System components are configured and managed securely.", "description": "Hardening baseline documentation", "kind": "control", "parent": null @@ -8444,7 +8444,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 3.4", - "title": "Req 3.4", + "title": "Access to displays of full PAN and ability to copy PAN is restricted.", "description": "Memory store review, PAN protection evidence", "kind": "control", "parent": null @@ -8457,7 +8457,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 3.5", - "title": "Req 3.5", + "title": "Primary account number (PAN) is secured wherever it is stored.", "description": "Encryption configuration, key management records", "kind": "control", "parent": null @@ -8470,7 +8470,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 4.2", - "title": "Req 4.2", + "title": "PAN is protected with strong cryptography during transmission.", "description": "TLS configuration, protocol verification", "kind": "control", "parent": null @@ -8483,7 +8483,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 5.2", - "title": "Req 5.2", + "title": "Malicious software (malware) is prevented, or detected and addressed.", "description": "Integrity check configuration, verification records", "kind": "control", "parent": null @@ -8502,7 +8502,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 6.3", - "title": "Req 6.3", + "title": "Security vulnerabilities are identified and addressed.", "description": "Vulnerability scan results, patch records", "kind": "control", "parent": null @@ -8515,7 +8515,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 6.4", - "title": "Req 6.4", + "title": "Public-facing web applications are protected against attacks.", "description": "WAF configuration, protection evidence", "kind": "control", "parent": null @@ -8546,7 +8546,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 7.2", - "title": "Req 7.2", + "title": "Access to system components and data is appropriately defined and assigned.", "description": "Access control matrix for agent tools, privilege review records", "kind": "control", "parent": null @@ -8559,7 +8559,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 7.3", - "title": "Req 7.3", + "title": "Access to system components and data is managed via an access control system(s).", "description": "Periodic access review records", "kind": "control", "parent": null @@ -8572,7 +8572,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 8.2", - "title": "Req 8.2", + "title": "User identification and related accounts for users and administrators are strictly managed throughout an account's lifecycle.", "description": "Account inventory, unique account evidence", "kind": "control", "parent": null @@ -8585,7 +8585,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 8.3", - "title": "Req 8.3", + "title": "Strong authentication for users and administrators is established and managed.", "description": "Credential management policy, rotation records", "kind": "control", "parent": null @@ -8598,7 +8598,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 10.2", - "title": "Req 10.2", + "title": "Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.", "description": "Audit log configuration, sample log entries", "kind": "control", "parent": null @@ -8617,14 +8617,14 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 10.7", - "title": "Req 10.7", + "title": "Failures of critical security control systems are detected, reported, and responded to promptly.", "description": "Monitoring configuration, alert records, detection evidence", "kind": "control", "parent": null }, { "control_id": "Req 11.3", - "title": "Req 11.3", + "title": "External and internal vulnerabilities are regularly identified, prioritized, and addressed.", "description": "Pen test report with goal hijack test cases", "kind": "control", "parent": null @@ -8643,7 +8643,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 12.3", - "title": "Req 12.3", + "title": "Risks to the cardholder data environment are formally identified, evaluated, and managed.", "description": "Risk analysis for agentic AI in PCI scope", "kind": "control", "parent": null @@ -8674,7 +8674,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "Req 12.6", - "title": "Req 12.6", + "title": "Security awareness education is an ongoing activity.", "description": "Training curriculum, completion records", "kind": "control", "parent": null @@ -8728,6 +8728,11 @@ window.CROSSWALK_FRAMEWORKS = [ "date": "2026-09-18", "change": "Migrated off the swapped-column ids of issue #35: 72 items -> 49", "author": "OWASP GenAI Data Security Initiative" + }, + { + "date": "2026-09-18", + "change": "Titled 17 entries that had carried only their identifier, from the published text: PCI DSS v4.0 requirement headings, transcribed from PCI SSC \"PCI DSS v4.0 SAQ D for Merchants\" — Req 1.3, Req 2.2, Req 3.4, Req 3.5, Req 4.2, Req 5.2, Req 6.3, Req 6.4, Req 7.2, Req 7.3, Req 8.2, Req 8.3, Req 10.2, Req 10.7, Req 11.3, Req 12.3, Req 12.6", + "author": "OWASP GenAI Data Security Initiative" } ] }, @@ -9075,7 +9080,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "P7.1", - "title": "P7.1", + "title": "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.", "description": "Accuracy review procedures", "kind": "control", "parent": null @@ -9098,7 +9103,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "control_id": "PI1.3", - "title": "PI1.3", + "title": "The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.", "description": "Output quality controls, factual accuracy testing", "kind": "control", "parent": null @@ -9114,6 +9119,11 @@ window.CROSSWALK_FRAMEWORKS = [ "date": "2026-09-18", "change": "Migrated off the swapped-column ids of issue #35: 209 items -> 46", "author": "OWASP GenAI Data Security Initiative" + }, + { + "date": "2026-09-18", + "change": "Titled 2 entries that had carried only their identifier, from the published text: TSP section 100, 2017 Trust Services Criteria (with Revised Points of Focus — 2022) — P7.1, PI1.3", + "author": "OWASP GenAI Data Security Initiative" } ], "inventory_completeness": {