1.1 Install and maintain a firewall configuration to protect cardholder data.
Firewalls are devices that control computer traffic allowed between an entity’s networks (internal) and untrusted networks (external), as well as traffic into and out of more sensitive areas within an entity’s internal trusted networks. This requirement involves the use of firewalls to create a virtual barrier around the organization’s network, protecting sensitive cardholder data from unauthorized access.
1.2 Do not use vendor-supplied defaults for system passwords and other security parameters.
System components like routers, switches, firewalls, and servers often come with default passwords set by the vendor to help with initial installation and setup. These passwords are usually common and well-known to attackers, and they’ll often try these defaults first when attempting to compromise a system.
This requirement mandates the changing of these default passwords before the system is used in a live environment. It also implies that other security parameters should be appropriately configured in line with industry best practices and your organization’s security policies. This could include things like disabling unnecessary services or accounts, setting password complexity requirements, enabling logging, and more.
By doing these two things—installing and maintaining a secure firewall configuration and not using vendor-supplied defaults for system passwords and security parameters—an organization can substantially reduce the risk of a data breach or other security incidents.