1.2 NSCs are configured and maintained
How to meet it
Define a configuration standard, restrict changes via change control, and review rule sets at least every six months.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 1.2, in plain English.
1.2.1Configuration standards for network security control rulesets are defined, implemented, and maintained.
1.2.2Any change to network connections or NSC configurations goes through the formal change control process.
1.2.3An accurate network diagram showing every connection between the CDE and other networks, including wireless, is kept current.
1.2.4An accurate data-flow diagram showing how account data moves across systems and networks is maintained and updated on change.
1.2.5Every allowed service, protocol, and port is identified, approved, and tied to a documented business need.
1.2.6Security features are defined and applied for any insecure service, protocol, or port still in use.
1.2.7NSC configurations are reviewed at least once every six months to confirm they remain relevant and effective.
1.2.8NSC configuration files are protected from unauthorized access and kept consistent with the live configuration.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Network security policyUse for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4.
Open the control-to-policy map← 1.1 Processes and mechanisms are defined and understood1.3 Network access to and from the CDE is restricted →
Back to Requirement 1, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.