PCI DSS 1.2.7: Configurations of NSCs are reviewed at least once every six months to confirm they are relevant

PCI DSS v4.0.1 control 1.2.7: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 1.2.

Requirement 1: Install and Maintain Network Security Controls › Section 1.2

Configurations of NSCs are reviewed at least once every six months to confirm they are relevant and effective.

Summary

Review the configuration of your network security controls at least every six months, and remove or fix anything that no longer has a business reason.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
1.2.7.a Examine documentation to verify procedures are defined for reviewing configurations of NSCs at least once every six months.
1.2.7.b Examine documentation of reviews of configurations for NSCs and interview responsible personnel to verify that reviews occur at least once every six months.
1.2.7.c Examine configurations for NSCs to verify that configurations identified as no longer being supported by a business justification are removed or updated.

Six months, not annually. This is one of the semi-annual cadences that entities schedule yearly out of habit, and a review performed once in the twelve months before the assessment fails on the frequency alone. The teeth are in procedure 1.2.7.c: configurations no longer supported by a business justification are removed or updated. That makes this a control with an outcome, not a look. A review that lists stale rules and leaves them in place has been performed and has not been passed. What you review against is the list from 1.2.5, which is why the two controls are best worked together.

What to prepare

  • The documented review procedure, stating the six-month frequency.
  • The last two reviews, dated, so the interval is visible rather than asserted.
  • What each review found, and what happened to it.
  • Current configuration, to show the removals actually landed.

How to implement it

1. Schedule it twice a year with the dates fixed in advance. Reviews that are triggered by the assessment approaching are visible as such from the dates alone.

2. Review against the approved list, not against opinion. Any rule not on the 1.2.5 list is either missing from the list or should not be there, and both outcomes are useful.

3. Close the loop in the same cycle. 1.2.7.c is examined against the configuration, so a finding carried into the next review is a finding that has not been addressed.

4. Use hit counters where the platform has them. A rule that has matched no traffic in six months is the easiest conversation about business justification you will have.

Where this commonly fails

  • Reviewed annually, which fails the frequency however good the review is.
  • Findings recorded and rules left in place, failing 1.2.7.c while satisfying 1.2.7.b.
  • Both reviews performed in the same quarter, so the interval between them is not six months.
  • The review covering the perimeter and skipping internal segmentation controls, which are also NSCs.

Others in section 1.2:

Control What it requires
1.2.1 Configuration standards for NSC rulesets…
1.2.2 All changes to network connections and to configurations of NSCs are approved and managed…
1.2.3 An accurate network diagram(s) is maintained that shows all connections between the CDE…
1.2.4 An accurate data-flow diagram(s) is maintained that meets…
1.2.5 All services, protocols, and ports allowed are identified, approved…
1.2.6 Security features are defined and implemented for all services, protocols…
1.2.8 Configuration files for NSCs…

1.2.6 · All controls · 1.2.8

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.