PCI DSS 1.3.3: NSCs are installed between all wireless networks and the CDE

PCI DSS v4.0.1 control 1.3.3: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 1.3.

Requirement 1: Install and Maintain Network Security Controls › Section 1.3

NSCs are installed between all wireless networks and the CDE, regardless of whether the wireless network is a CDE, such that:

  • All wireless traffic from wireless networks into the CDE is denied by default.
  • Only wireless traffic with an authorized business purpose is allowed into the CDE.

Summary

Put a network security control between every wireless network and the cardholder data environment, deny wireless traffic into it by default, and allow only what has a business reason.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
1.3.3 Examine configuration settings and network diagrams to verify that NSCs are implemented between all wireless networks and the CDE, in accordance with all elements specified in this requirement.

The phrase that decides this control is "regardless of whether the wireless network is a CDE". It is easy to read 1.3.1 and 1.3.2 as already covering this, since they govern traffic into and out of the CDE generally. They do not close it. 1.3.3 says that wireless is treated as untrusted even when the wireless network is itself in scope, so a WLAN that is part of the CDE still needs an NSC between it and the rest of the CDE. Wireless gets its own control because association is not a physical act: someone in the car park is on the same segment as someone at a desk.

What to prepare

  • A network diagram showing every wireless network, including guest, corporate, warehouse, point-of-sale and anything vendor-installed.
  • The NSC ruleset governing each wireless segment, with the default-deny rule visible.
  • The business justification for each allowed wireless-to-CDE flow, naming the application and the owner.

How to implement it

1. Find every wireless network first, not just the ones IT built. Assessors regularly find access points installed by a store fit-out, a vendor, or a facilities contractor, and an access point nobody owns is still yours for this control.

2. Terminate wireless on its own segment and route it through an NSC. Bridging wireless directly into a wired VLAN that touches the CDE leaves nothing to enforce.

3. Make the deny explicit. The requirement says denied by default. A ruleset that happens to have no permit is not the same evidence as a ruleset that ends in a deny rule you can point at.

4. Justify each allowed flow in writing. "Only wireless traffic with an authorized business purpose" is tested by asking what the purpose is, and the answer has to be more specific than "the tills need the network".

Where this commonly fails

  • Assuming a wireless network that is already in scope does not need an NSC between it and the CDE.
  • Guest wireless treated carefully and corporate wireless treated as trusted, when the control does not distinguish.
  • Access points installed by a third party during a fit-out and never added to the diagram.
  • A rule permitting the whole wireless subnet to the CDE because one handheld device needed one port.

Others in section 1.3:

Control What it requires
1.3.1 Inbound traffic to the CDE is restricted…
1.3.2 Outbound traffic from the CDE is restricted…

1.3.2 · All controls · 1.4.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.