Network Segmentation

Also: Segmentation, Isolation

PCIComplianceHubLast updated

Dividing a network into isolated segments using firewalls, routing controls or equivalent, so traffic between them is controlled rather than unrestricted. In PCI DSS, segmentation is the main lever for reducing scope: it separates the cardholder data environment from the rest of the network so unrelated systems fall outside the assessment. It is not itself a requirement, and an organization may run a flat network if it chooses, but then every system on that network is in scope. Where segmentation is relied on to reduce scope, it must be proven by segmentation penetration testing, and a failed test collapses the scope reduction with it.

Applies to. Any entity that wants systems outside the CDE to be out of scope. It is optional: a flat network is allowed, and then every system on it is in scope.
Example. The card-processing subnet is reachable from the office network only through a firewall that allows one management host on one port. Office workstations are then out of scope. If the firewall also allows file sharing from the office, they are not.
Limits. Segmentation reduces scope only if it is effective, and effectiveness is proven by penetration testing of the segmentation controls at least every 12 months and after any change to them (11.4.5), every six months for service providers (11.4.6). A VLAN alone is not segmentation unless traffic between VLANs is controlled. Section 4 of the standard describes what adequate segmentation isolates and what it does not.
In PCI DSS v4.0.1. 1.3.1, 11.4.5, 11.4.6