Segmentation is a key strategy for meeting PCI DSS 2.0
One of the cornerstones of network defense is through protecting sensitive data by segmenting it from other parts of the network. When was the last time you saw a castle built with hundreds of doors to the outside? They don’t build them that way, because it’s hard enough to keep a bunch of dudes with swords and large rocks from killing, you without having to watch all of those doors too.
Protecting the network isn’t much different, in that its considered good security practices to block access to applications and services that are not or should not be used. Segmentation of these protected applications and systems is the first step. With the release of PCI Data Security Standard (DSS) 2.0 in October, segmentation is more important that ever, especially when considering virtualization technologies.
PCI does not specifically require segmentation in any of the 12 sections of the DSS, but does mention its importance in defining what is considered in “scope” from a PCI prospective. If cardholder data is sent across the same network infrastructure as users, printers, video cameras, and other network devices those devices must also be considered for compliance with PCI. Obviously this can make a PCI audit extremely difficult and costly. Segmenting cardholder data, and systems that process that data, can prevent co-mingling sensitive traffic flows with the rest of the network reducing what needs to be inspected and audited. Decreasing the scope for PCI will also tend to reduce the cost of an audit because less time is spent inspecting “extraneous” devices and systems.
There are many ways to segment traffic; the most common and rudimentary method is through the use of a simple vlan. Access rules can be implemented on switches and routers to preform policy segmentation. In addition VRF’s (virtual routing and forwarding) is becoming increasingly popular as a way to segment traffic through the creation of a “virtual” network that operates independently with its own routing tables and addressing structure. Virtualizing the network can dramatically reduce the scope of a PCI audit without massive amounts of re-architecting.
Some organizations also choose to deploy NAC as a means to segment and authenticate the network as well. This type of design will provide a logical network overlay that not only allows for authentication and role based access, but security policy assessment and remediation of policy violations too. Firewalls are often used as well to provide segmentation and access control between network boundaries. In addition to blocking traffic that does not meet policy requirements, a firewall can be joined with an IPS to inspect application traffic for malicious activity providing visibility into the network beyond the port and address level. You can never have too many options when developing your strategy for meeting compliance requirements.
Regardless of how you segment the network, segment you must in order to meet PCI roles without breaking you neck auditing your ip enabled automatic plant watering device. In our big old Borderless Network world, the physical edges of the network may be eroding but the need to segment network zones of trust has not diminished at all. The more thought you put into how data flows through the network will pay off in simpler audits and much less stress when meeting compliance requirements. Who knows, if you do a really good job, your PCI auditor may even give you a gold star! So, how do you address segmentation today? Please share your thoughts in the comments below.




