Build and maintain a secure network and systems

Requirement 2: Apply secure configurations to all system components

Default passwords and settings are public knowledge. Every component must be hardened before it goes live.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 2 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • Base hardening on a recognised benchmark (e.g. CIS) and enforce it with configuration management.
  • Keep an inventory of components mapped to their configuration standard.

Evidence to keep

  • Hardening/configuration standards
  • System inventory
  • Sample configurations showing defaults changed

Example

A team builds servers from a CIS-hardened image via Terraform, with no default credentials and only required ports open, recorded in an inventory.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map