Build and maintain a secure network and systems

Requirement 1: Install and maintain network security controls

Network security controls (NSCs), such as firewalls, control traffic between your cardholder data environment (CDE) and everything else.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 1 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • Segment the CDE so PCI scope is as small as possible, this is the single biggest cost saver.
  • Diagram every connection into and out of the CDE; auditors expect a current network and data-flow diagram.

Evidence to keep

  • Network and data-flow diagrams
  • Firewall/security-group rule sets
  • Six-monthly rule-review records

Example

A merchant places card-processing servers in an isolated VPC subnet, allows only HTTPS from the app tier and outbound to the payment gateway, denies everything else, and reviews the rules each quarter.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map