PCI DSS 1.2.3: An accurate network diagram(s) is maintained that shows all connections between the CDE
PCI DSS v4.0.1 control 1.2.3: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 1.2.
Requirement 1: Install and Maintain Network Security Controls › Section 1.2
An accurate network diagram(s) is maintained that shows all connections between the CDE and other networks, including any wireless networks.
Summary
Keep a current network diagram showing every connection between the cardholder data environment and any other network, wireless included.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 1.2.3.a | Examine diagram(s) and network configurations to verify that an accurate network diagram(s) exists in accordance with all elements specified in this requirement. |
| 1.2.3.b | Examine documentation and interview responsible personnel to verify that the network diagram(s) is accurate and updated when there are changes to the environment. |
The topology counterpart to 1.2.4, which is the data-flow diagram. They are different documents and entities routinely maintain one and offer it for both: 1.2.3 shows what connects to what, 1.2.4 shows where account data goes. An assessor asks for both and will notice. Two things in the wording do work. "Including any wireless networks" is called out because wireless is the connection most often left off, which is also why 1.3.3 exists. And procedure 1.2.3.b tests that the diagram is updated when there are changes to the environment, so this is a maintenance obligation rather than an artefact: a diagram that was accurate in March and is offered in November has failed even if nothing has moved, because there is no process behind it.
What to prepare
- The network diagram itself, dated, with a version and an owner.
- Network configurations to check it against, since 1.2.3.a compares the two.
- The trigger that causes it to be updated, and evidence of the last time that trigger fired.
- The list of third-party and remote connections, which are the ones most often absent.
How to implement it
1. Draw the boundary, not the whole estate. The requirement is about connections between the CDE and other networks. A diagram of every switch in the company is harder to keep accurate and answers the question less clearly.
2. Include the connections that are not yours. Vendor VPNs, managed service provider links, payment gateway connections and remote access paths are all connections between the CDE and another network.
3. Tie the update to change control. 1.2.2 already routes network changes through a process; adding "does this change the diagram" to that process is what makes 1.2.3.b answerable.
4. Put cloud on it. VPCs, peering, transit gateways and private endpoints are network connections. A diagram showing the data centre and stopping at the cloud boundary is inaccurate in the way this control is testing for.
Where this commonly fails
- One diagram offered as both the network diagram and the data-flow diagram.
- Accurate at the last assessment and updated annually, so it documents history rather than the environment.
- Wireless omitted, which the requirement names specifically.
- Third-party connections missing, because they were arranged by a business team rather than by the network team.
Related controls
Others in section 1.2:
| Control | What it requires |
|---|---|
| 1.2.1 | Configuration standards for NSC rulesets… |
| 1.2.2 | All changes to network connections and to configurations of NSCs are approved and managed… |
| 1.2.4 | An accurate data-flow diagram(s) is maintained that meets… |
| 1.2.5 | All services, protocols, and ports allowed are identified, approved… |
| 1.2.6 | Security features are defined and implemented for all services, protocols… |
| 1.2.7 | Configurations of NSCs are reviewed at least once every six months to confirm they are relevant… |
| 1.2.8 | Configuration files for NSCs… |
← 1.2.2 · All controls · 1.2.4 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.