Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Insight

PCI compliant network design: segment, restrict and document

PCI compliant network design keeps card data in a small, well-guarded part of your network. So the assessment covers fewer systems, and an intruder finds fewer paths.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Pci compliant network design: segment card data, restrict traffic and document it

Principles of PCI compliant network design

Good design starts with separation. Systems that handle card data sit apart from everything else. Therefore office laptops, guest Wi-Fi and development servers cannot reach them freely.

Also, traffic is allowed only when there is a business reason. Everything else is denied by default.

Building blocks of PCI compliant network design

The standard calls these network security controls. However, the idea is simple.

ControlPurpose
SegmentationSeparates the cardholder data environment
Restricted inbound and outbound trafficOnly necessary connections allowed
Wireless isolationNo path from Wi-Fi into card systems
Secured admin accessMFA and controlled jump points

PCI compliant network design check

Tick what is true and documented.

Your result appears here as you tick, so you can see what is still open.

Documentation in PCI compliant network design

PCI DSS expects a current network diagram and a data flow diagram. Also, rules need a documented reason and regular review.

  • Network diagram showing all connections to card data
  • Data flow diagram for each payment channel
  • Rule sets with business justification
  • Review records at least every six months

Testing the design

A design is only as good as its proof. Therefore segmentation is tested at least annually for merchants, and after significant changes. Also, rule reviews catch permissions that crept in.

In addition, cloud environments need the same thinking. Security groups and virtual networks play the role of firewalls.

Where Winslow helps

We review designs, diagrams and rule sets before assessment. We are not a QSA. Gap analysis generally runs $8,000 to $40,000, with remediation on top. Requirements are in the PCI SSC document library.

Also involve the people who run the network day to day. Because they know the exceptions, they spot paths that diagrams miss. So reviews become more accurate. In addition, record each approved exception with an owner and an end date, because temporary rules tend to become permanent.

PCI compliant network design questions

Is segmentation required in PCI compliant network design?

It is not mandatory, but without it the whole network falls in scope.

How often should PCI compliant network design be reviewed?

Rule sets at least every six months, and diagrams whenever the network changes.

Does PCI compliant network design apply in the cloud?

Yes. Security groups and virtual networks do the same job.

Who tests segmentation?

A qualified, independent tester, at least annually for merchants.

Related guides

Review your PCI compliant network design

Send a rough description of your network. We reply in writing, usually within one business day.

Ask us anything