Trusted Network

PCIComplianceHubLast updated

A network the entity controls or manages and that meets the PCI DSS requirements that apply to it. Its opposite, an untrusted network, is one outside the entity's control, or inside it but not meeting the requirements. The line between the two is where Requirement 1's network security controls go.

Applies to. Every entity; 1.4 is written entirely in terms of the boundary between trusted and untrusted networks.
Example. The CDE segment is trusted. The internet is untrusted. So is a guest wireless network the entity runs, because it does not meet the requirements, and so is a partner's network however friendly. 1.4.1 requires network security controls between the two, 1.4.2 restricts inbound traffic from untrusted networks to what is necessary, 1.4.3 stops spoofed internal addresses arriving from outside, and 1.4.4 keeps stored cardholder data off systems reachable from untrusted networks.
Limits. Trust is earned by control and compliance, not by ownership: an entity's own flat office network with no controls is untrusted with respect to the CDE. 1.5.1 extends the boundary to computing devices that connect to both, such as laptops that go home, which need their own controls.
In PCI DSS v4.0.1. 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.5.1