{"id":4275,"date":"2016-12-16T11:52:38","date_gmt":"2016-12-16T16:52:38","guid":{"rendered":"http:\/\/3dmerchant.com\/blog\/?p=4275"},"modified":"2021-12-03T03:23:53","modified_gmt":"2021-12-03T08:23:53","slug":"pci-security-standards-council-publishes-supplemental-pci-dss-scoping-guidance","status":"publish","type":"post","link":"https:\/\/3dmerchant.com\/blog\/merchant-processing-security\/pci-compliance-merchant-processing-security\/pci-security-standards-council-publishes-supplemental-pci-dss-scoping-guidance","title":{"rendered":"PCI SECURITY STANDARDS COUNCIL PUBLISHES SUPPLEMENTAL PCI DSS SCOPING GUIDANCE"},"content":{"rendered":"<p>Guidance Clarifies Scoping Principles Outlined in the PCI Data Security Standard \u2014<br \/>\nWAKEFIELD, Mass., 9 December 2016 \u2014 Incorrectly identifying where and how payment data is at risk in an organization\u2019s systems continues to lead to data breaches. Today, the PCI Security Standards Council (PCI SSC) published Guidance for PCI DSS Scoping and Network Segmentation to help businesses address this challenge.<\/p>\n<p>PCI Data Security Standard (PCI DSS) Requirement 1.1 states that organizations need to maintain a cardholder data flow diagram to help identify which systems are in scope and need protection. Yet data breach investigation reports continue to find that companies suffering compromises were unaware that cardholder data was present on their compromised systems. This guidance provides a method to help organizations identify systems that, at a minimum, need to be included in scope for PCI DSS. It includes guidance on how segmentation can be used to help reduce the number of systems that require PCI DSS controls and illustrative examples of some common segmentation approaches.<\/p>\n<blockquote><p>\n\u201cFor years, we have preached the need to simplify and minimize the footprint of cardholder data,\u201d said PCI SSC Chief Technology Officer Troy Leach. \u201cOne way to accomplish this is through good segmentation. It allows an organization to focus their attention on a limited number of assets and more readily address security issues as they arise. As a result, it should also reduce the level of effort to comply with PCI DSS.\u201d<\/p><\/blockquote>\n<p>While segmentation is not a PCI DSS requirement, it is a strongly recommended practice. Segmentation of networks included in or connected to the cardholder data environment is important for organizations as it can limit the exposure of payment data in a system, simplify PCI DSS compliance efforts and reduce the chance of being targeted by a criminal. However, as improper segmentation can put cardholder data at risk, it\u2019s critical that organizations understand and implement segmentation properly.<\/p>\n<p>The guidance was developed with industry input and collaboration in order to address common questions from PCI SSC stakeholders on scoping and segmentation. Christian Janoff, PCI SSC Board of Advisor member and Security Solutions Architect for Cisco, works regularly with merchants using scoping and segmentation products and was a leading contributor to the guidance. \u201cKnowing the scope of your cardholder data environment and properly segmenting to protect it has been a challenge for many organizations. By providing guidance, we hope this will help to simplify the process, making it easier to secure payment card data,\u201d he said. \u201cWe at Cisco are proud to partner with the Council and industry peers to bring additional scoping and segmentation guidance to the industry.\u201d<\/p>\n<p>Guidance for PCI DSS Scoping and Network Segmentation is intended for organizations looking to understand scoping and segmentation principles when applying PCI DSS to their environments. It also provides a method for facilitating effective scoping discussions between entities and is useful for:<\/p>\n<ul>\n<li>\u2022 Merchants, acquirers, issuers, service providers (issuer processors, token service providers, and others) responsible for meeting PCI DSS requirements for their enterprises;<br \/>\n\u2022 Assessors responsible for performing PCI DSS assessments;<br \/>\n\u2022 Acquirers evaluating merchants\u2019 or service providers\u2019 PCI DSS compliance documentation;<br \/>\n\u2022 PCI Forensic Investigators (PFI) responsible for determining PCI DSS scope as part of an investigation.<\/li>\n<\/ul>\n<p>It is important to note each organization is responsible for making its own scoping decisions and that following this guidance does not guarantee that effective segmentation has been implemented, nor does it guarantee compliance with PCI DSS. The guidance is available on the PCI SSC website. Chief Technology Officer Troy Leach provides additional insights on the topic on the PCI Perspectives blog.<\/p>\n<p><strong>About the PCI Security Standards Council<\/strong><br \/>\nThe PCI Security Standards Council is a global forum that is responsible for the development, management, education, and awareness of the PCI Data Security Standard (PCI DSS) and other standards that increase payment data security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Guidance Clarifies Scoping Principles Outlined in the PCI Data Security Standard \u2014 WAKEFIELD, Mass., 9 December 2016 \u2014 Incorrectly identifying where and how payment data is at risk in an organization\u2019s systems continues to lead to data breaches. Today, the &hellip; <a href=\"https:\/\/3dmerchant.com\/blog\/merchant-processing-security\/pci-compliance-merchant-processing-security\/pci-security-standards-council-publishes-supplemental-pci-dss-scoping-guidance\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[142],"tags":[39],"class_list":["post-4275","post","type-post","status-publish","format-standard","hentry","category-pci-compliance-merchant-processing-security","tag-pci-compliance"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/4275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/comments?post=4275"}],"version-history":[{"count":1,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/4275\/revisions"}],"predecessor-version":[{"id":4276,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/4275\/revisions\/4276"}],"wp:attachment":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/media?parent=4275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/categories?post=4275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/tags?post=4275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}