PCI DSS Requirement 1 Explained: Install and Maintain Network Security Controls

Share:
PCI DSS Requirement 1 installs and maintains network security controls to protect cardholder data. Learn firewall configuration, segmentation, and compliance requirements.

TL;DR

  • Requirement 1 mandates installing and maintaining network security controls (firewalls, routers, security groups) to restrict access to cardholder data environments and prevent direct public access to sensitive systems.
  • Network segmentation isolates the Cardholder Data Environment (CDE) from untrusted networks, reducing audit scope and significantly lowering compliance costs while strengthening security posture.
  • Configuration and documentation of firewall rules, access controls, and roles require regular maintenance and testing every six months, ensuring controls remain effective against evolving threats.

PCI DSS Requirement 1: Install and Maintain Network Security Controls mandates that organizations establish and maintain robust network security infrastructure to protect cardholder data from unauthorized access. This requirement applies to all entities that store, process, or transmit card data, whether merchants, service providers, acquirers, or payment processors.

The “network security controls” referenced in Requirement 1 extend beyond traditional firewalls. The current PCI DSS v4.0 standard recognizes that modern organizations use diverse technologies to control traffic: physical firewalls in on-premises data centers, cloud security groups in AWS or Azure environments, next-generation firewalls with advanced threat inspection, and network access control lists (ACLs). All these tools accomplish the same goal: restricting traffic to only what’s necessary for business operations.

Why is Requirement 1 the foundation? Because access controls must be applied at network boundaries before data even reaches systems. If an attacker gains access to your network, having strong encryption and access controls on individual systems provides secondary protection. But preventing unauthorized network access stops threats at the perimeter.

What are the Key Components of Requirement 1

Network Security Controls (NSCs)

Firewalls or equivalent technologies that monitor and filter incoming and outgoing network traffic. These controls must be configured with explicit allow rules, specifying what traffic is permitted, rather than default deny rules that require administrators to think through every potential legitimate connection.

Cardholder Data Environment (CDE)

The subset of your network where cardholder data is stored, processed, or transmitted. The CDE forms the scope of your PCI DSS compliance obligations. A smaller, well-defined CDE dramatically reduces audit complexity and compliance burden.

Network Segmentation

The practice of dividing your network into isolated zones using firewalls and security controls. Segmentation separates the CDE from systems that don’t need access to cardholder data such as guest WiFi, development environments, or corporate email servers.

Trusted vs. Untrusted Networks

PCI DSS classifies networks as either trusted (those assessed for PCI compliance) or untrusted (those not assessed). Your firewall configuration must restrict all connections between untrusted networks and CDE systems.

PCI DSS Requirement 1 Sub-Requirements: What You Must Implement

PCI DSS restructured Requirement 1 into five sub-requirements:

1.1: Processes and Mechanisms for Managing Network Security Controls

Your organization must document procedures for configuring firewalls, assign roles and responsibilities, establish change management processes, and conduct regular reviews of firewall rules at least every six months.

1.2: Network Security Controls Are Configured and Maintained

Firewall configurations must restrict inbound and outbound traffic, manage configuration files securely, change vendor defaults, and document disabled services and ports.

1.3: Network Access to and from the Cardholder Data Environment Is Restricted

Direct public access to cardholder data systems must be prohibited. Wireless networks must be segmented from the CDE, and personal firewalls must be installed on portable devices connecting to cardholder systems.

1.4: Segmentation Isolates the CDE from Other Parts of the Network

Properly segmented environments exclude non-CDE systems from audit scope, reducing compliance costs. Segmentation controls are tested at least every six months.

1.5: Risks from Dual-Connected Devices Are Mitigated

Devices connecting to both untrusted networks and cardholder systems must be managed through prohibition, separate network interfaces, endpoint protection, or controlled temporary connections.

How Network Segmentation Reduces PCI DSS Compliance Scope

Network segmentation remains one of the highest-impact controls for organizations pursuing PCI DSS compliance.
Without segmentation, your entire network becomes in-scope if cardholder data touches even one system. Audit costs scale with network complexity, and compliance timelines extend significantly.

By implementing segmentation, you create a defined CDE that includes only systems touching cardholder data. This provides immediate benefits:

  • Audit scope shrinks to 20-40% of pre-segmentation size
  • Audit costs decrease proportionally
  • Remediation efforts focus on critical systems
  • Compliance timelines compress from months to weeks

An organization with 500 servers might find only 50 within the CDE scope after segmentation, a potential savings of $50,000-$150,000 annually in audit and remediation expenses.

Implementing PCI DSS Requirement 1: Six Practical Steps

Step 1: Map every system that touches cardholder data, including payment processing systems, payment applications, database servers, backup systems, and administrator access points.

Step 2: Design your firewall architecture to place at least one firewall between the internet and all cardholder data systems, restricting outbound connections to business-required destinations only.

Step 3: Configure firewalls with explicit allow rules, implement the principle of least privilege, adopt a default-deny posture, require documented authorization for changes, and log all triggered rules.

Step 4: Document formal policies addressing network architecture, firewall configuration standards, roles and responsibilities, review procedures, and business justifications for allowed services.

Step 5: Establish a six-month (or quarterly) firewall rule review cycle to verify necessity, identify outdated rules, remove unnecessary rules, document findings, and update network documentation.

Step 6: Implement network segmentation to reduce scope, build dedicated CDE zones, control inter-zone traffic with firewalls, test segmentation every six months, and document the architecture.

People Also Ask:

What is PCI DSS Requirement 1?

Requirement 1 mandates installing and maintaining network security controls to protect cardholder data systems from unauthorized access and restrict traffic to only what’s necessary for business operations.

Do I need network segmentation for PCI DSS?

Segmentation is not mandatory but significantly reduces audit scope, costs, and effort. Organizations typically reduce PCI scope by 60-80%, translating to substantial compliance savings.

Can cloud environments use security groups instead of firewalls?

Yes. PCI DSS v4.0 recognizes security groups as equivalent network security controls. The principle is identical: restrict traffic to only necessary connections.

Ready to Secure Your Payment Networks?
Partner with Ampcus Cyber for PCI DSS consulting services help payment processors, merchants, and service providers achieve certification while reducing audit costs.

Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert