PCI_DSS_v4Requirement 1voice-validated
PCI_DSS_v4 R1: Requirement 1
PCI_DSS_v4
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Network security controls (NSCs), such as firewalls and other network security technologies, are network policy enforcement points that typically control network traffic between two or more logical or physical network segments based on pre-defined policies or rules. PCI DSS Requirement 1 covers establishing and maintaining NSCs that protect the cardholder data environment.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 0
| Mitigation | What it does | Confidence |
|---|
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-284 | 1. Improper access control on network devices or segments directly violates PCI DSS Requirement 1's mandate for secure network policies. | 90% |
| CWE-285 | 1. Improper authorization for network resources, a failure of PCI DSS Requirement 1, allows unauthorized access to the CDE. | 80% |
| CWE-295 | 1. Improper certificate validation can compromise secure network communication, undermining PCI DSS Requirement 1's objectives for data protection. | 70% |
| CWE-306 | 1. Missing authentication for critical network functions or devices, contrary to PCI DSS Requirement 1, creates significant vulnerabilities. | 80% |
| CWE-319 | 1. Cleartext transmission of sensitive information over the network, without protection, directly contradicts PCI DSS Requirement 1's security goals. | 80% |
| CWE-693 | 1. Protection mechanism failure in network security controls represents a direct non-compliance with PCI DSS Requirement 1, exposing the CDE. | 90% |
| CWE-732 | 1. Incorrect permission assignment for critical network resources or configurations undermines the security posture required by PCI DSS Requirement 1. | 80% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0173 compute · voice-rubric self-validated