{"id":1250,"date":"2021-03-26T07:51:26","date_gmt":"2021-03-26T07:51:26","guid":{"rendered":"https:\/\/www.pcidssguide.com\/?p=1250"},"modified":"2023-10-09T16:25:21","modified_gmt":"2023-10-09T16:25:21","slug":"how-to-prepare-network-documentation-for-pci-dss-compliance-requirements","status":"publish","type":"post","link":"https:\/\/pcidssguide.com\/how-to-prepare-network-documentation-for-pci-dss-compliance-requirements\/","title":{"rendered":"How to Prepare Network Documentation for PCI DSS Compliance Requirements?"},"content":{"rendered":"\n\n\n\n\n

PCI DSS requires organizations to establish and maintain a secure network with a secure configuration of firewalls and routers. By taking advantage of network security controls, organizations can prevent criminals from accessing payment system networks and stealing cardholder data.<\/p>\n\n\n\n

The development and maintenance of network documentation are covered by PCI DSS Requirements 1.1.2 and 1.1.3. Basically, network documentation consists of a network diagram and data flow diagram.<\/p>\n\n\n\n

See Also: PCI DSS Requirement 1 Explained<\/a><\/strong><\/p>\n\n\n\n

Some of the diagrams’ requirements include the creation of network infrastructure and data flow diagrams for the Cardholder Data Environment (CDE). Correct documentation assures both your company and your QSA that your network is set up securely.<\/p>\n\n\n\n

See Also: PCI DSS Network and Data Flow Diagrams<\/a><\/strong><\/p>\n\n\n\n

PCI DSS Requirement 1.1.2 states that organizations must have an existing network diagram that defines all connections between the Cardholder Data Environment (CDE) and other networks, including all wireless networks.<\/p>\n\n\n\n

See Also: PCI DSS Firewall Requirements<\/a><\/strong><\/p>\n\n\n\n

PCI DSS Requirement 1.1.3 requires organizations to have an up-to-date diagram showing all cardholder data flows between systems and networks.<\/p>\n\n\n\n

Network documentation is essential for network maintenance, security design, and incident response tasks. Network documentation will always be essential for your institution. Network diagrams help define and visualize the entire PCI DSS scope or CDE.<\/p>\n\n\n\n

Your network documentation should include the following:<\/p>\n\n\n\n