---
title: "Requirement 1.1.1: Building and Maintaining Effective Network Security Policies and Procedures"
description: Learn how to document, maintain, communicate, and enforce network security policies and procedures to meet PCI DSS Requirement 1.1.1.
---

[Understanding PCI-DSS](https://www.borderhawk.com/understanding-pci-dss)

# [Requirement 1.1.1: Building and Maintaining Effective Network Security Policies and Procedures](https://www.borderhawk.com/understanding-pci-dss/pci-dss-requirement-1.1.1)

 Written by [Derek Rogers](https://www.borderhawk.com/understanding-pci-dss/author/derek-rogers) | Sep 29, 2026, 5:33:26 PM

### Requirement Information

Parent Requirement 1.1

Processes and mechanisms for installing and maintaining network security controls are defined and understood.

PCI DSS Requirement 1.1.1

All Security policies and operational procedures that are identified in Requirement 1 are:

- Documented
- Kept up to date
- In use
- Known to all affected parties

Priority: 6 (Lowest out of 6)

Priority Meaning: Complete remaining compliance efforts, and ensure all controls are in place. This milestone completes PCI DSS requirements and finishes all remaining related policies, procedures, and processes needed to protect the cardholder data environment. 

 

### Summary of Control Requirements

Requirement 1.1.1 mandates that organizations formally manage the policies and procedures supporting PCI DSS Requirement 1. Organizations must create, maintain, and update security policies and operational procedures. Additionally, these documents must be actively followed and communicated to personnel responsible for implementing or supporting network security controls.

A frequent misconception is that compliance is achieved solely through documentation. However, PCI DSS requires that policies and procedures accurately reflect current practices. Personnel must understand their responsibilities, and organizations must demonstrate that documented processes are consistently followed.

To ensure compliance, organizations should be able to address the following four questions:

1. Are the required policies and procedures formally documented?
2. Are these policies and procedures reviewed and updated in response to relevant changes?
3. Are personnel consistently adhering to these policies and procedures?
4. Do all affected individuals understand the requirements outlined in the policies and procedures?

If any of these questions cannot be answered affirmatively, the organization may face challenges in demonstrating compliance with Requirement 1.1.1. 

 

#### Why This Requirement Exists

Network security controls, including firewalls, routers, cloud security groups, network segmentation controls, and access control lists, are essential for protecting cardholder data. However, these technologies are only effective when administrators manage them consistently and according to clear guidance.

Requirement 1.1.1 establishes the governance framework for Requirement 1 by ensuring that expectations are documented, responsibilities are clearly communicated, and processes are consistently repeatable.

In the absence of documented and maintained procedures, the following risks may arise:

- Operational changes may be implemented inconsistently.
- Security configurations may gradually deviate from established standards.
- Different administrators may implement network security controls inconsistently.
- Essential reviews of security controls may be omitted.
- Organizations may become reliant on undocumented, experience-based knowledge.

Applicability of the Self-Assessment Questionnaire (SAQ)

Requirement 1.1.1 is included under PCI DSS Requirement 1 and is typically applicable in all contexts where Requirement 1 applies. This includes;

- SAQ A-EP
- SAQ C
- SAQ C-VT
- SAQ D (Merchant)
- SAQ D (Service Provider)

Since SAQ applicability may differ based on the payment environment and the validation method employed, organizations should consult the latest PCI SSC SAQ guidance to verify applicability. 

 

#### Scope

Requirement 1.1.1 applies to the management of security policies and operational procedures governing network security controls that protect the PCI DSS environment.

PCI DSS requirements apply to the **Cardholder Data Environment (CDE)**, which is comprised of:

- System components, people, and processes that store, process, or transmit cardholder data and/or sensitive authentication data; and
- System components that may not store, process, or transmit cardholder data or sensitive authentication data but have unrestricted connectivity to systems that do.

PCI DSS also applies to:

- System components, people, and processes that could impact the security of cardholder data and/or sensitive authentication data.

**Definition: Cardholder Data Environment (CDE)**  
The Cardholder Data Environment (CDE) encompasses the people, systems, networks, and processes responsible for storing, processing, transmitting, or protecting payment card data.

Examples include payment applications, firewalls that protect payment systems, payment databases, network administrators, and documented procedures that support these systems. 

 

### Understanding the Requirement

Although Requirement 1.1.1 may initially appear to be a documentation requirement, it is fundamentally a governance requirement.

The objective is to ensure that all network security activities addressed in Requirement 1 are conducted in a controlled and repeatable manner.

The requirement establishes four expectations.

Policies and Procedures Must be Documented

Personnel must not rely on memory or verbal instructions when managing network security controls. Expectations must be documented and readily accessible.

Examples may include:

> - Firewall management policies
> - Network security standards
> - Rule review procedures
> - Network configuration procedures
> - Segmentation validation procedures

Policies and Procedures Must be Kept up to Date

Documentation must accurately reflect the current management of network security controls.

Documentation must be updated promptly to reflect changes in technologies, responsibilities, or processes.

Assessment failures often occur when procedures describe activities that are no longer performed or reference obsolete technologies.

Policies and Procedures Must be in Use

Well-written policies have limited value if they are not consistently followed by personnel.

Assessors routinely compare documented procedures with actual practices. Major discrepancies between documentation and operational practices may result in compliance concerns.

Policies and Procedures Must be Known to Affected Parties

Relevant personnel must understand the policies and procedures applicable to their responsibilities.

For example:

> - Firewall administrators should understand firewall management procedures.
> - Network engineers should understand change control requirements.
> - Managers should understand approval responsibilities.
> - Security personnel should understand review requirements.

Posting a document in a repository alone does not demonstrate personnel awareness. 

 

### Additional Technical Details

Organizations commonly establish a hierarchical documentation structure to support Requirement 1.

Security Policy

Defines management expectations and objectives.

Example:

> Network security controls must be implemented and managed to ensure the protection of the Cardholder Data Environment.

Standard

Defines mandatory requirements.

Example:

> Firewall rule reviews must be conducted at a minimum of every six months.

Procedure

Describes the process by which the activity is performed.

Example:

> The firewall administrator exports active rules, reviews the business justification, obtains management approval, and stores the review records.

 

### How to Meet Requirement 1.1.1

Requirement 1.1.1 may be satisfied through several practical approaches.

Option 1: Centralized Policy Management

All PCI-related policies and procedures should be maintained in a centralized repository.

Benefits:

- Version control
- Easier employee access
- Centralized updates
- Consistent document management

Example:

> - SharePoint
> - Document management systems
> - Governance, risk, and compliance platforms
> - Internal policy portals

Option 2: Formal Review Process

Periodic reviews of Requirement 1 documentation should be established.

Common review frequencies include:

- Annual
- Semi-annual
- Following significant changes

An effective review process should verify the following elements:

- Accuracy
- Applicability
- Assigned responsibilities
- References to technologies
- Current organizational structure

Option 3: Change-Driven Updates

Documents should be updated whenever significant changes occur, rather than waiting for an annual review.

Examples include:

> - Firewall replacement
> - Cloud migration
> - Network redesign
> - Organizational restructuring
> - New service providers

This approach is consistent with PCI DSS guidance, which recommends updating documents as soon as possible following changes.

Option 4: Formal Communication and Acknowledgment

Personnel may be required to formally acknowledge policies and procedures.

Examples include:

> - Annual policy attestation
> - Security awareness platforms
> - Learning management systems
> - Signed acknowledgments

This process demonstrates that affected individuals are aware of their responsibilities. 

 

### Evidence Expectations

Baseline Evidence Requirements

Organizations are generally expected to maintain the following:

- Requirement 1 policies
- Requirement 1 procedures
- Document revision history
- Published document copies
- Employee communication records

Enhanced Evidence for Maturity

Organizations demonstrating higher maturity often maintain the following:

- Formal review records
- Document approval workflows
- Policy acknowledgments
- Change records showing updates after technology changes
- Management reviews
- Training records

Frequently Missing Evidence

Assessors frequently identify gaps in the following areas:

- Outdated procedures
- Missing review documentation
- No proof personnel received policies
- Processes being performed differently than documented
- Documents referencing obsolete systems

 

### Compensating Controls and Customized Approaches

Customized Approach Objective

PCI DSS defines the customized approach objective as:

*Expectations, controls, and oversight for meeting activities within Requirement 1 are defined, understood, and adhered to by affected personnel. All supporting activities are repeatable, consistently applied, and conform to management’s intent.*

Organizations that adopt a customized approach must provide evidence that their practices consistently achieve the intended outcome.

Practical Customized Approach Examples

Examples of customized approaches include the following:

> - Alternative methods for distributing policies
> - Different training methods for communicating procedures
> - Customized workflow systems used for document management

Regardless of the implementation method, organizations must ensure that documentation is current, accessible, clearly understood, and consistently followed.

Compensating Controls

Compensating controls are generally less common for Requirement 1.1.1 because the requirement focuses primarily on governance and documentation practices.

Any compensating control must provide equivalent assurance that policies and procedures are documented, maintained, utilized, and understood.

SMB Considerations

Most small and mid-sized organizations are advised to adopt the standard approach instead of implementing customized approaches or compensating controls.

Simple and well-maintained policies and procedures are generally easier to implement, assess, and maintain at a lower cost. 

 

### Demonstrating Compliance

Assessors generally require evidence addressing all four elements of the compliance requirement:

- Documented
- Kept up to date
- In use
- Known to affected parties

Relevant types of evidence include the following:

Documentation Evidence

- Policies
- Standards
- Procedures
- Version histories
- Review records

Operational Evidence

- Completed firewall reviews
- Change records
- Approval records
- Network security management activities

Personnel Evidence

- Training records
- Policy acknowledgments
- Interview responses
- Responsibility assignments

 

### Testing Procedures

Examine documentation and interview personnel to verify that security policies and operational procedures identified in Requirement 1 are managed in accordance with all elements specified in this requirement.

The assessor seeks to verify the following criteria:

1. Required documents exist.
2. Documents are current.
3. Personnel understand their responsibilities.
4. Actual practices match documented procedures.

The assessor does not merely confirm the existence of policies. Instead, the assessor seeks evidence that these policies are operationalized and consistently implemented.

What to Expect During an Assessment

The assessor may:

- Review policies and procedures.
- Examine revision histories.
- Review evidence of policy distribution.
- Interview firewall administrators.
- Interview network engineers.
- Interview management personnel.
- Compare documented procedures to actual practices.

Organizations should be prepared to explain both the content of their documentation and the mechanisms used to ensure employee compliance. 

 

## Common Mistakes

Treating the Requirement as a Documentation Exercise

Many organizations mistakenly assume that having a written policy alone is sufficient.

PCI DSS requires that documentation be maintained, actively followed, and effectively communicated.

Updating Documents Only Once per Year

Although annual reviews are valuable, delaying updates until the next scheduled review after significant infrastructure changes can result in documentation remaining inaccurate for extended periods.

Relying on Tribal Knowledge

Organizations may rely on the expertise of experienced administrators instead of establishing and adhering to documented procedures.

This reliance introduces operational risk, which frequently becomes evident during personnel interviews.

Failing to Demonstrate Awareness

Organizations may possess comprehensive documentation but lack evidence that personnel have reviewed or understood its contents.

Overengineering the Documentation Program

Some organizations develop numerous highly complex documents, although simpler and more maintainable documentation would achieve the same objectives.

Excessive documentation frequently leads to outdated procedures and an increased administrative burden. 

[View full post](https://www.borderhawk.com/understanding-pci-dss/pci-dss-requirement-1.1.1)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Derek Rogers"
  },
  "dateModified" : "2026-09-29T17:55:43.646Z",
  "datePublished" : "2026-09-29T17:33:26Z",
  "headline" : "Requirement 1.1.1: Building and Maintaining Effective Network Security Policies and Procedures",
  "image" : {
    "@type" : "ImageObject",
    "height" : 60,
    "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
    "width" : 60
  },
  "mainEntityOfPage" : "https://www.borderhawk.com/understanding-pci-dss/pci-dss-requirement-1.1.1",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Understanding PCI-DSS"
  }
}
```