Firewall
PCIComplianceHubLast updated
Hardware or software that permits or denies traffic between networks of different trust levels according to a set of rules. PCI DSS v4.x replaced the word with network security controls, because the function can now be performed by cloud security groups, host firewalls, virtual appliances and routers as well as by a box called a firewall.
Applies to. Every boundary between the CDE and any other network, and between trusted and untrusted networks. Requirement 1 governs the controls, whatever they are called.
Example. A cloud security group that allows only the payment application's port from the web tier to the database tier is a firewall in the standard's sense, and its rule set is subject to the six-monthly review in 1.2.7 like any other.
Limits. Renaming the concept was the point: an entity with no firewall appliance still has network security controls to configure (1.2), to restrict inbound and outbound CDE traffic with (1.3), and to place between trusted and untrusted networks (1.4). Rules that accumulate without review are the commonest Requirement 1 finding, which 1.2.7 exists for, and 1.2.5 requires every allowed service, protocol and port to have an approved business need.