Requirement 1: Install and maintain network security controls
Network security controls (NSCs), such as firewalls, control traffic between your cardholder data environment (CDE) and everything else.
Sub-requirements
Processes and mechanisms are defined and understood
2 defined requirementsDocument NSC policies and assign ownership; keep them current and known to staff.
View defined requirements →NSCs are configured and maintained
8 defined requirementsDefine a configuration standard, restrict changes via change control, and review rule sets at least every six months.
View defined requirements →Network access to and from the CDE is restricted
3 defined requirementsAllow only necessary traffic in and out of the CDE; deny all else by default.
View defined requirements →Network connections between trusted and untrusted networks are controlled
5 defined requirementsPlace NSCs at the boundary and restrict inbound/outbound traffic to what is authorised.
View defined requirements →Risks from devices connecting to both untrusted networks and the CDE are mitigated
1 defined requirementHarden laptops/endpoints that can reach the CDE (e.g. host firewalls, restrictions).
View defined requirements →Tips
- ›Segment the CDE so PCI scope is as small as possible, this is the single biggest cost saver.
- ›Diagram every connection into and out of the CDE; auditors expect a current network and data-flow diagram.
Evidence to keep
- ✓Network and data-flow diagrams
- ✓Firewall/security-group rule sets
- ✓Six-monthly rule-review records
Example
A merchant places card-processing servers in an isolated VPC subnet, allows only HTTPS from the app tier and outbound to the payment gateway, denies everything else, and reviews the rules each quarter.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.