Compliance guidance
PCI DSS 6.4.3 script controls
Build a payment-page script inventory and preserve authorization, business justification, and integrity evidence for scoped review.
Last reviewed September 12, 2026
PCI DSS v4.0.1 Requirement 6.4.3 addresses the management of scripts loaded and executed on payment pages. Use SiteWall observations to build a scoped script inventory, connect each script to authorization and business justification, and review available integrity context. SiteWall supplies technical records; the organization and its assessor remain responsible for applicability, control design, and compliance conclusions.
PCI DSS payment-page script inventory
The Script Register identifies payment-page resources observed by SiteWall and records authorization and business justification. Review each script’s identity, provider, page scope, observation context, integrity information, and decision history; unresolved or undocumented resources remain visible for follow-up.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Observed scripts | Review observed scripts in the active project, follow the linked source record, and preserve its observation, interpretation, and owner decision context. |
| Scope | Keep the selected project, monitored pages, traffic paths, and observation period attached to the result. |
| Authorization | Review authorization in the active project, follow the linked source record, and preserve its observation, interpretation, and owner decision context. |
| Justification | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
PCI DSS 6.4.3 support
For PCI DSS requirement 6.4.3, SiteWall can support payment-page script inventory, observed resource context, authorization, business justification, integrity records, and review history. The organization still owns process design, approvals, change control, personnel responsibilities, and the final assessment conclusion.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Records SiteWall supplies | Review the records SiteWall supplies in the active project, follow the linked source record, and preserve its observation, interpretation, and owner decision context. |
| Organizational inputs still needed | Confirm the active organization and project, the person or team accountable for the change, and the role required to perform it. Verify the resulting access or ownership state from a second authorized context when practical. |