PCI-1.2.1:

From HORSE - Holistic Operational Readiness Security Evaluation.
Revision as of 13:39, 27 February 2007 by Mdpeters (talk | contribs)
Jump to navigation Jump to search

Choose a sample size of twenty-five percent of the population of all firewalls, routers, and routing infrastructure gear. An even distibution should come from the following locations:

1: Between the Internet and the DMZ.
2: Between the DMZ and the internal network.


Note: The sample should include the chokepoint router at the Internet, the DMZ router and firewall, the DMZ cardholder network segment, the perimeter router, and the internal cardholder network segment.

Examine firewall and router configurations to verify that inbound and outbound traffic is limited to:

  • Web protocols (HTTP, HTTPS).

--Mdpeters 08:32, 27 February 2007 (EST)