PCI DSS 1.2.4: An accurate data-flow diagram(s) is maintained that meets
PCI DSS v4.0.1 control 1.2.4: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 1.2.
Requirement 1: Install and Maintain Network Security Controls › Section 1.2
An accurate data-flow diagram(s) is maintained that meets the following:
- Shows all account data flows across systems and networks.
- Updated as needed upon changes to the environment.
Summary
Keep a data-flow diagram that shows every path account data takes, and update it when the environment changes.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 1.2.4.a | Examine data-flow diagram(s) and interview personnel to verify the diagram(s) show all account data flows in accordance with all elements specified in this requirement. |
| 1.2.4.b | Examine documentation and interview responsible personnel to verify that the data-flow diagram(s) is accurate and updated when there are changes to the environment. |
Two bullets, and the second is where this fails: an accurate diagram is a maintained one. 1.2.4.a examines the diagram against the requirement, 1.2.4.b interviews personnel to verify it is kept current, which means someone has to be able to say when it was last revisited and why. This is also the diagram 12.5.2 asks you to update during scope validation, so the two controls are usually evidenced together, and a scope exercise that does not change the diagram is a signal, not a pass.
What to prepare
- The data-flow diagram, showing flows rather than only topology: where account data enters, moves, rests and leaves.
- A revision history, dated, so currency is demonstrable rather than asserted.
- The trigger in your change process that causes it to be revisited.
How to implement it
1. Draw the data, not the network. A network diagram shows what connects to what; this control asks where account data goes. The two look similar and answer different questions, and only the second satisfies 1.2.4.a.
2. Include the third parties. A flow that leaves for a payment provider and returns is part of the picture, and it is the part a fully outsourced merchant most needs to be able to show.
3. Cover every stage. Authorisation is the one everyone draws; settlement, refunds and chargebacks move account data too, and 12.5.2 names them explicitly.
4. Attach the update to the change process. A diagram maintained on request is a diagram maintained annually. Making a scope-affecting change ask "does this alter the data flow?" is what keeps it accurate.
Where this commonly fails
- A network topology diagram submitted as a data-flow diagram.
- One diagram for the main channel, with phone orders or a legacy flow undocumented.
- Accurate at the last assessment and untouched since, which the interview finds.
- Third-party flows drawn as a single box labelled with the provider, hiding whether account data crosses your systems.
Related controls
Others in section 1.2:
| Control | What it requires |
|---|---|
| 1.2.1 | Configuration standards for NSC rulesets… |
| 1.2.2 | All changes to network connections and to configurations of NSCs are approved and managed… |
| 1.2.3 | An accurate network diagram(s) is maintained that shows all connections between the CDE… |
| 1.2.5 | All services, protocols, and ports allowed are identified, approved… |
| 1.2.6 | Security features are defined and implemented for all services, protocols… |
| 1.2.7 | Configurations of NSCs are reviewed at least once every six months to confirm they are relevant… |
| 1.2.8 | Configuration files for NSCs… |
← 1.2.3 · All controls · 1.2.5 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.