Requirement 1 · Install and maintain network security controls

1.2 NSCs are configured and maintained

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL1.2 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Define a configuration standard, restrict changes via change control, and review rule sets at least every six months.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 1.2, in plain English.

1.2.1Configuration standards for network security control rulesets are defined, implemented, and maintained.
1.2.2Any change to network connections or NSC configurations goes through the formal change control process.
1.2.3An accurate network diagram showing every connection between the CDE and other networks, including wireless, is kept current.
1.2.4An accurate data-flow diagram showing how account data moves across systems and networks is maintained and updated on change.
1.2.5Every allowed service, protocol, and port is identified, approved, and tied to a documented business need.
1.2.6Security features are defined and applied for any insecure service, protocol, or port still in use.
1.2.7NSC configurations are reviewed at least once every six months to confirm they remain relevant and effective.
1.2.8NSC configuration files are protected from unauthorized access and kept consistent with the live configuration.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 1, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.