Network Segmentation
Network segmentation is the practice of dividing a larger computer network into smaller, separated sections or zones so that systems in one section cannot freely communicate with systems in another. Organizations use devices such as firewalls, switches, and routers to create and enforce these boundaries. In payment security, segmentation is commonly used to help limit which systems can reach the environment that handles cardholder data.
Network segmentation is an architectural approach that divides a network into multiple isolated segments or subnets, each functioning as its own smaller network, with traffic between segments controlled and restricted by enforcement points such as firewalls, switches, and routers. In a PCI DSS context, segmentation is not itself a mandatory requirement but is a technique frequently used to isolate the cardholder data environment (CDE) from out-of-scope systems, potentially reducing the systems, people, and processes that fall within assessment scope. Effective segmentation depends on the strength and validation of the isolating controls rather than on network design intent alone; connectivity that allows a system to affect the security of the CDE keeps that system in scope. Readers should confirm segmentation guidance and any scope-reduction expectations against the current published PCI DSS standard, as wording and expectations differ between versions.
Why it matters
Network segmentation matters in payment security primarily because it can influence the scope of a PCI DSS assessment. When the cardholder data environment (CDE) is isolated from the rest of an organization's network, the systems, people, and processes that fall within assessment scope may be reduced. A flat, unsegmented network, by contrast, can pull large portions of an organization's infrastructure into scope, because any system able to reach or affect the security of the CDE is generally considered in scope.
Beyond scope considerations, segmentation supports a broader defense-in-depth posture. By restricting which systems can communicate with the CDE, segmentation is intended to make lateral movement across a network more difficult, so that a compromise of one zone does not automatically grant access to systems handling cardholder data. It is important to note that segmentation reduces risk rather than eliminates it: its effectiveness depends on the strength and correct configuration of the isolating controls, not on network diagrams or design intent alone.
Under PCI DSS, network segmentation is a technique organizations may choose to use rather than a mandatory requirement. Because connectivity that allows a system to affect the security of the CDE keeps that system in scope, poorly validated or misconfigured segmentation can create a false sense of scope reduction. Readers should confirm segmentation guidance and any scope-reduction expectations against the current published PCI DSS standard, as wording and expectations differ between versions.
Who it's relevant to
Inside Network Segmentation
Common questions
Answers to the questions practitioners most commonly ask about Network Segmentation.