Network Security Controls
Network Security Controls (NSCs) are technologies that manage and restrict traffic moving between different parts of a network, allowing intended connections while blocking unwanted ones. Firewalls are the most familiar example, but other network technologies can act as NSCs as well. In payment security, they are used to help protect systems that store, process, or transmit cardholder data by controlling what can reach those systems.
In PCI DSS v4.0, the term 'network security controls (NSCs)' replaced the earlier terminology centered on 'firewalls and routers' to describe network technologies that act as policy enforcement points, controlling network traffic between two or more logical or physical network segments based on defined rules. NSCs are the subject of PCI DSS Requirement 1, which addresses installing and maintaining such controls, including provisions that NSC configurations be defined, maintained, and periodically reviewed; confirm exact requirement numbering and wording against the current published standard, as these differ between versions. Firewalls are a common implementation, but an NSC may be any qualifying network security technology serving as an enforcement point. Note that the broader phrase 'network security control' is used generically across other frameworks (for example, ISO/IEC 27001 Annex A) and is not exclusive to PCI DSS; the NSC term and its specific control expectations described here derive from PCI DSS Requirement 1.
Why it matters
Systems that store, process, or transmit cardholder data are exposed to risk whenever untrusted networks can reach them directly. Network Security Controls (NSCs) are the mechanism PCI DSS relies on to define and enforce which connections are permitted between network segments, helping to limit the paths an attacker could use to reach sensitive systems. Without properly configured NSCs, a compromise in one part of a network can more easily spread toward the systems handling payment data.
The move to NSC terminology in PCI DSS v4.0 reflects the reality that a firewall is no longer the only technology that can act as a policy enforcement point. By describing the control by its function rather than by a single product type, the standard accommodates a range of network security technologies while keeping the underlying objective constant: controlling traffic between logical or physical network segments based on defined rules. This matters for compliance validation, because assessors evaluate whether the enforcement point does what is required, not whether it carries a particular label.
Because NSC configurations tend to accumulate rules over time, they can drift from their intended state, leaving overly permissive access that widens exposure. PCI DSS therefore treats ongoing maintenance and periodic review of NSC configurations as part of the control, not a one-time setup task. Note that exact requirement numbering and review intervals differ between PCI DSS versions and should be confirmed against the current published standard rather than assumed.
Who it's relevant to
Inside NSCs
Common questions
Answers to the questions practitioners most commonly ask about NSCs.