pci-ngfw-compliance

Maps firewall controls and evidence to PCI DSS v4.0.1 requirements for compliance assessment.

9|Updated Mar 7, 2026
One-click install
npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill pci-ngfw-compliance-fastrevmd-lab
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pci-ngfw-compliance
Source: https://github.com/fastrevmd-lab/fwskillsshare/tree/main/skills/pci-ngfw-compliance
Command: npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill pci-ngfw-compliance-fastrevmd-lab

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security engineers and assessors struggle to translate raw firewall configurations into defensible PCI DSS v4.0.1 evidence, often overclaiming that an NGFW is "PCI compliant" when compliance actually applies to the entire environment, scope, and operational controls. ## Core Features & Use Cases - Requirement Mapping: Maps firewall controls to specific PCI DSS requirement IDs including Requirement 1 (network security controls), 6.4.2 (web application protection), 8.x (authentication/MFA), 10.x (logging), and 11.x (IDS/IPS and segmentation testing). - Assessment Workflow: Provides a nine-step workflow covering CDE scoping, rulebase review, inbound/outbound validation, segmentation testing, and logging verification, plus an evidence request checklist. - Evidence Markers: Defines a standard PCI:/REQ: description and tag pattern for marking PCI-relevant policies, NAT rules, zones, and objects directly in firewall configs. - Use Case: Given an exported SRX or Fortinet rulebase, produce an assessor-ready summary mapping each finding to PCI DSS requirement IDs with evidence references, open gaps, and remediation recommendations. ## Quick Start Use the pci-ngfw-compliance skill to assess this firewall configuration export against PCI DSS v4.0.1 Requirement 1 and produce a gap summary.

Frequently Asked Questions about pci-ngfw-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess firewall rules against PCI DSS v4.0.1?

Establish CDE scope and data flows first, then map each rule touching the CDE to requirement IDs such as 1.3.1 (inbound) and 1.3.2 (outbound). Record owner, business justification, ticket reference, logging, and hit counts for every rule, and verify an explicit final deny.

Is an NGFW PCI compliant by itself?

No. PCI DSS compliance is assessed for the entity and its in-scope environment, not a product. An NGFW can support Requirement 1 and other controls only when properly configured, monitored, reviewed every six months, and backed by evidence.

Does an NGFW IPS satisfy PCI DSS 11.5.1 automatically?

Not automatically. You must verify IPS placement at the CDE perimeter and critical points, confirm signatures and engines are up to date, and evidence alert routing and response. Coverage gaps or alert-only profiles without rationale are common findings.

Can firewall segmentation reduce PCI DSS scope?

Yes, but only if the segmentation controls are validated by penetration testing covering both inside and outside perspectives. VLANs, zones, or security groups alone do not reduce scope without documented test evidence and repeat testing after significant changes.

What evidence should I request before a PCI firewall assessment?

Request the CDE asset inventory, network and data-flow diagrams, firewall configuration and rulebase exports, NAT and VPN configs, rule owner justifications, six-month review records, change tickets, SIEM log samples, IDS/IPS status, and segmentation test reports.

When should I use this instead of a general firewall audit?

Use it when findings must map to PCI DSS requirement IDs or assessor evidence such as ROC or SAQ support. For framework-neutral configuration hygiene without compliance mapping, a general firewall best-practices audit is the better fit.