Contents
Is network segmentation a PCI DSS requirement?
PCI network segmentation is a key security practice—not a requirement—for any company that wants to protect its cardholder data and reduce its PCI DSS compliance scope.
What is CDE for PCI?
The CDE is composed of the people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data. Point-of-sale (POS) systems including payment terminals, cash registers, card readers, or any other system that processes PCI data from a customer.
Are PA DSS applications in scope for PCI DSS?
Use of a PA-DSS compliant application by itself does not make an entity PCI DSS compliant, since that application must be implemented into a PCI DSS compliant environment and according to the PA-DSS Implementation Guide provided by the payment application vendor (per PA-DSS Requirement 13).
Does PCI DSS apply to me?
A: The PCI DSS applies to ANY organization, regardless of size or number of transactions, that accepts, transmits or stores any cardholder data.
What is the difference between PA-DSS and PCI DSS?
The difference between the two is relatively straightforward: PCI-DSS applies to all companies that store, process, or transmit cardholder data, whereas PA-DSS applies to vendors that produce and sell payment applications. The PCI SSC maintains and updates the set of standards collectively known as PCI.
What is the goal of PA-DSS?
The goal of PA-DSS is to help software vendors and others develop secure payment applications that do not store prohibited data, such as full magnetic stripe, CVV2 or PIN data, and ensure their payment applications support compliance with the PCI DSS.
What does CDE stand for in PCI DSS?
The cardholder data environment (CDE) is comprised of people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data. PCI DSS applies to all system components included in or connected to the CDE.
When is a system in scope for PCI DSS?
In a flat network, all systems are in scope if any single system stores, processes, or transmits account data. Note that public, untrusted networks (for example, the Internet) are not in scope for PCI DSS.
What does segmentation mean in the PCI DSS?
This is a long-standing misunderstanding within the community that when PCI DSS talks about segmentation, it means isolation ( which is clearly documented within the PCI DSS standard itself ). “The intent of segmentation is to prevent out-of-scope systems from being able to communicate with systems in the CDE or impact the security of the CDE.
When does scoping apply to a CDE system?
The following scoping concepts always apply: Systems located within the CDE are in scope, irrespective of their functionality or the reason why they are in the CDE. Similarly, systems that connect to a system in the CDE are in scope, irrespective of their functionality or the reason they have connectivity to the CDE.