PCI-DSS requires specific network controls in your cardholder data environment (CDE).
Segmentation. Isolate card-processing systems from the rest of your network. Fewer systems in scope means lower audit costs.
Firewall rules:
- Document all CDE connections
- Deny all by default
- Review rules every months
Wireless:
- Change vendor defaults
- WPA minimum encryption
- Quarterly rogue AP scans
DMZ required for public-facing servers. No direct internet access from the CDE.