{
  "node_id": "pci-dss-v4-requirement-7",
  "title": "PCI DSS v4 Req 7 (Access Control)",
  "domain": "Cloud & SaaS",
  "version": "1.1.1",
  "last_updated": "2026-04-30",
  "bluf": "Payment Card Industry Data Security Standard v4 Requirement 7 mandates a stringent framework for restricting access to system components and cardholder data based on an explicit business need-to-know. Compliance necessitates that a formal access control policy is defined and actively maintained. Pursuant to governing standards, system access must be structured upon an implemented role-based access control methodology, ensuring that permissions are assigned based on job classification and function. A foundational \"default deny-all\" configuration is required, meaning access is prohibited unless specifically permitted. This enforces the least privilege principle, where personnel receive only the minimum permissions necessary to perform their duties. The process for granting access must follow a documented approval workflow, with all subsequent privilege assignments being formally recorded. Furthermore, these access rights are subject to periodic validation, requiring a comprehensive review at a minimum frequency of every 6 months. A defined termination revocation process must ensure immediate removal of access for departing personnel. Authoritative guidance also stipulates that both system account access and user access to security functions must be rigorously restricted. Critically, all user interactions within the Cardholder Data Environment (CDE) are to be logged, creating an auditable trail of data access and system activities to prevent unauthorized exposure.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-210-cloud-access-control",
    "pci-dss-v4-requirement-8"
  ],
  "primary_citations_count": 6
}