| Framework | PCI-DSS v4.0 |
|---|---|
| Control ID | 1.3 |
| Control Family | Network Access Control |
| Control Name | Network Access |
| Status | NOT APPLICABLE |
| Assessment Date | 2026-04-19T03:34:43.008438+00:00 |
| Assessor | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
| Environment Scope | Azure: Pay-As-You-Go (prod) (4f29d094-1079-44c9-acb0-4d73a7a2dd34) |
| Report ID | e59403fb457962f3e90363c240a1dfad179a2f173e8f3771dc7b4a3f6c9db338 |
Network access to and from the cardholder data environment (CDE) is restricted.
Source: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf
Each implementation specification addressed separately per HIPAA §164.306(d) / NIST 800-53A assessment methodology.
1.3.1 Inbound traffic to the CDE is restricted: only traffic that is necessary is allowed and all other traffic is specifically denied
Summarized with counts + exceptions + drill-down. Raw data available on request per retention policy.
Test of Design (does the control exist?) + Test of Operating Effectiveness (does it work consistently?). Sampling per AICPA AU-C 530.
n/a (policy review)
Policy documents align with control objective.
AICPA 25-sample of qualifying events over 90-day window
Sampled events comply with policy. No exceptions identified.
Click any finding to view detail, remediation, and record an exception (risk acceptance). Exceptions are retained in the report as part of the audit trail.
cfg-drift-detected
Control 1.3: partial implementation detected on sampled configuration.
▾
SOC 2 Type 2 and HITRUST assessors require management's written response to findings.
| Scanner | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
|---|---|
| Scanner version | v2.0.1 |
| Collection timestamp | 2026-04-19T03:34:43.008438+00:00 |
| Retention | 2555 days (HIPAA 164.316(b)(2)) |
| Report hash (SHA-256) | e59403fb457962f3e90363c240a1dfad179a2f173e8f3771dc7b4a3f6c9db338 |
This same evidence is admissible for the following related controls. Scan once, satisfy multiple frameworks.
AC-2, IA-2, SC-8, SC-13 — same evidence satisfies§164.312 — same evidence satisfiesCC6.1, CC6.6, CC6.7 — same evidence satisfies