PCI DSS 4.2.1.2: Wireless networks transmitting PAN or connected to the CDE use industry best practices
PCI DSS v4.0.1 control 4.2.1.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 4.2.
Requirement 4: Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks › Section 4.2
Wireless networks transmitting PAN or connected to the CDE use industry best practices to implement strong cryptography for authentication and transmission.
Summary
Wireless that carries card numbers or touches the cardholder data environment uses strong cryptography for both authentication and transmission.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 4.2.1.2 | Examine system configurations to verify that wireless networks transmitting PAN or connected to the CDE use industry best practices to implement strong cryptography for authentication and transmission. |
Two things, and entities usually do one of them well. Transmission is the encryption of the traffic, which WPA2 or WPA3 handles. Authentication is how a device proves it belongs, and a pre-shared key handles that badly: everyone who has ever been told the key can authenticate, which is also why 2.3.2 has to rotate it whenever someone who knew it leaves. "Industry best practices" is the standard declining to name a protocol, which means WEP and TKIP are clearly out and the current answer is WPA2-Enterprise or WPA3. The scope trigger is broad: transmitting PAN or connected to the CDE, so the corporate wireless that reaches the cardholder data environment is in scope even if no card number ever crosses it.
What to prepare
- Every wireless network in scope, from the same walk that supports 1.3.3.
- The security settings for each: protocol, cipher, and authentication method.
- Where 802.1X is used, the authentication infrastructure behind it.
How to implement it
1. Use WPA2-Enterprise or WPA3 rather than a shared key. It answers the authentication half properly, and it removes the rotation obligation in 2.3.2 at the same time, which is the argument that usually wins the budget.
2. Check the cipher, not just the protocol name. A network configured for WPA2 with TKIP available for compatibility is not using strong cryptography, and the fallback is where that happens.
3. Treat "connected to the CDE" as the real scope. The wireless most often missed is the ordinary corporate network that happens to route to the cardholder data environment.
4. Verify from a client, not from the controller. What the access point actually negotiates is the evidence, and it is occasionally not what the configuration page says.
Where this commonly fails
- Strong transmission encryption over a pre-shared key, satisfying half the requirement.
- Legacy ciphers left enabled for one old device, which makes the fallback available to everyone.
- A guest network correctly isolated and a corporate network that reaches the CDE left unexamined.
- Wireless installed by a vendor or a fit-out and never brought into the configuration standard.
Related controls
Others in section 4.2:
| Control | What it requires |
|---|---|
| 4.2.1 | Strong cryptography and security protocols… |
| 4.2.1.1 | An inventory of the entity’s trusted keys and certificates used to protect PAN during… |
| 4.2.2 | PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies |
← 4.2.1.1 · All controls · 4.2.2 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.