PCI DSS 4.0
Req 1: Network Security Controls

PCI DSS 4.0 1.3.1: 1.3.1 Inbound CDE traffic restricted

Traffic entering the cardholder data environment must be restricted so that (a) only necessary traffic is permitted and (b) everything else is explicitly denied. The guidance recommends evaluating all inbound traffic, wherever it originates, against authorised rules, for example by limiting source and destination addresses and ports. Applicability: no special notes; applies to every assessed entity. Customized approach objective: traffic that is not authorised is unable to get into the CDE.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 63 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 7 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-13.10 Perform Application Layer Filtering
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-3.12 Segment Data Processing and Storage Based on Sensitivity
  • CIS-4.4 Implement and Manage a Firewall on Servers
  • CIS-4.5 Implement and Manage a Firewall on End-User Devices

FedRAMP High · 7 controls

  • AC-17 Remote Access
  • AC-4 Information Flow Enforcement
  • SC-7 Boundary Protection
  • SC-7(3) Access Points
  • SC-7(4) External Telecommunications Services
  • SC-7(5) Deny by Default Allow by Exception
  • SI-4(4) Inbound and Outbound Communications Traffic

FedRAMP Moderate · 7 controls

  • AC-17 Remote Access
  • AC-4 Information Flow Enforcement
  • SC-7 Boundary Protection
  • SC-7(3) Access Points
  • SC-7(4) External Telecommunications Services
  • SC-7(5) Deny by Default Allow by Exception
  • SI-4(4) Inbound and Outbound Communications Traffic

NIST SP 800-53 Rev 5 · 5 controls

ISO 27001:2022 · 4 controls

  • 6.7 Remote working
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks
  • ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations
  • ANSSI-HYG-19 Segment the Network and Partition the Zones
  • ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration
  • NS-1 Establish network segmentation boundaries
  • NS-2 Secure cloud services with network controls
  • NS-3 Deploy firewall at the edge of enterprise network

ISO 27002:2022 · 3 controls

  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks

ISO 27701:2019 · 3 controls

  • 6.10 Communications security
  • 6.10.1 Network security management
  • 6.6.1 Business requirements of access control

NIST SP 800-171 Rev 3 · 3 controls

  • 03.01.03 Information Flow Enforcement
  • 03.13.01 Boundary Protection
  • 03.13.06 Network Communications - Deny by Default - Allow by Exception

UK Cyber Essentials · 3 controls

  • CE-FW.1 Boundary Firewalls Deployed
  • CE-FW.4 Approve and Document Inbound Rules
  • CE-FW.5 Remove or Disable Unused Rules
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)

C5 (Germany) · 2 controls

  • C5-COS-04 Cross-network access
  • C5-COS-06 Segregation of data traffic in jointly used network environments

CMMC 2.0 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.1.3e Employ Secure Information Transfer Solutions
  • 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation
  • P1-2.1.4 P1-2.1.4 Only necessary 3DS traffic permitted, rest denied
  • P2-3.1.1 P2-3.1.1 ACS and DS traffic limited to 3DS functions
  • SEC05-BP02 Control traffic flow within your network layers
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

SOC 2 · 1 control

  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 1: Network Security Controls

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 1.3.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.