PCI DSS Requirement 1.1.1: Implementing a Change Control Program
What is PCI Requirement 1.1.1? Your organization needs to ensure that you have the appropriate methods to control any changes into and out of your environment. PCI Requirement 1.1.1 requires, "a formal process for approving and testing all network connections and changes to the firewall and router configurations." The PCI DSS v3.2.1 states that PCI Requirement 1.1.1 exists because, "Without formal approval and testing of changes, records of the changes…