![]()
Network Configuration Management and PCI
Core to PCI compliance mandates is to ensure that only authorized personnel access or modify critical information. As such, most compliance initiatives have focused on securing and documenting the applications, databases and servers. They often overlook the role of the network. If the network is not secure, then unauthorized access can be made through infrastructure vulnerabilities — negating any efforts on the servers, applications, or databases.
This document reviews the PCI Standard and discusses how organizations can ensure network compliance with internal and PCI requirements.