What is the required review frequency for firewall & router rule sets per 1.1.7?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What is the required review frequency for firewall & router rule sets per 1.1.7?

Explanation:
Regularly reviewing firewall and router rulesets keeps access controls aligned with current security policies and the actual network design. Over time, rules can drift, become outdated, or accumulate unnecessary permissiveness, which can create gaps or risks. By performing a review at least every six months, you catch these drift issues before they become problems and ensure that only authorized rules are in place. This minimum interval balances security oversight with operational practicality. Annual reviews would miss changes that happen in six months, while more frequent reviews are acceptable but not required by the standard.

Regularly reviewing firewall and router rulesets keeps access controls aligned with current security policies and the actual network design. Over time, rules can drift, become outdated, or accumulate unnecessary permissiveness, which can create gaps or risks. By performing a review at least every six months, you catch these drift issues before they become problems and ensure that only authorized rules are in place. This minimum interval balances security oversight with operational practicality. Annual reviews would miss changes that happen in six months, while more frequent reviews are acceptable but not required by the standard.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy