On Sep. 9, PCI issued supplement for modern network architectures.
The PCI Security Standards Council (PCI SSC) published new Information Supplement, the PCI DSS Scoping and Segmentation Guidance for Modern Network Architectures.
Supplement Overview
Document was produced by 2023 Special Interest Group (SIG), the members of which provided extensive payment security expertise and technical knowledge on practices, guidance, and real-world scenarios for applying PCI DSS scoping and segmentation.
Adoption of modern network architectures, including those developed to support cloud services and zero trust networks, has become more prevalent in payment ecosystem.
It is now common to see hybrid cardholder data environment (CDE) setups that will include various multi-cloud environments, alongside traditional network architecture.
Organizations are trying to understand and address the impact this new technology is having on the now traditional PCI DSS scoping and segmentation practices in reality.
This new document provides guidance on best practices to consider in these scenarios.
It includes the Determining of the impact of any zero trust architecture on PCI DSS scope and network segmentation, as well as the process of Defining PCI DSS scope boundaries in micro-segmentation and multi-cloud implementations, under guidance.
Also, How to develop and maintain a PCI DSS asset inventory given the ephemeral nature of cloud-hosted microservices and systems, and Identifying risks associated with implementation of modern network architecture given modern system complexity.
Also Guidance on specific PCI DSS needs on verifying scope and segmentation control.
The guidance is intended for use by merchants, service providers, and assessors to provide entities with knowledge, actionable guidance, and practical examples to assist in defining PCI DSS scope, and apply segmentation practice in network architectures.
This document is supplemental and does not supersede or replace any PCI standard.