PCI-1.2.3:
Choose a sample size of twenty-five percent of the population of all firewalls, routers, and routing infrastructure gear. An even distibution should come from the following locations:
- 1: Between the Internet and the DMZ.
- 2: Between the DMZ and the internal network.
Note: The sample should include the chokepoint router at the Internet, the DMZ router and firewall, the DMZ cardholder network segment, the perimeter router, and the internal cardholder network segment.
Examine firewall and router configurations to verify that inbound and outbound traffic is limited to:
- Other allowed traffic required by the business and documented in the firewall policy.
--Mdpeters 08:41, 27 February 2007 (EST)