Build and Maintain a Secure Network and Systems
1
Install and Maintain Network Security Controls
Network security controls (NSCs) such as firewalls, cloud security groups, and software-defined networking tools regulate traffic between trusted and untrusted networks. This requirement mandates that all network connections to and from the cardholder data environment (CDE) are controlled, documented, and regularly reviewed.
Control Intent
Prevent unauthorised network access to systems that store, process, or transmit cardholder data by implementing and maintaining properly configured network security controls at all entry and exit points.
Common Failures
- Overly permissive "allow any" rules left in firewall configurations that expose the CDE to unauthorised traffic
- Failure to maintain an accurate and current network diagram, leading to undocumented connections to the CDE
- Neglecting to review firewall rules on the required six-month cadence, allowing obsolete rules to persist
- Missing personal firewalls on laptops or remote devices used by employees who access the CDE
- Using default vendor-supplied credentials on firewall management interfaces