Segmentation Penetration Testing
Segmentation penetration testing is a set of controlled tests used to confirm that networks kept separate from systems handling payment card data cannot actually reach or communicate with those sensitive systems. In simple terms, it checks that a less-secure network is truly isolated from a more-secure one, rather than just being labeled as separated. If the testing finds unexpected connectivity, it means the separation is not working as intended.
Segmentation penetration testing is a series of penetration tests intended to validate that networks and systems treated as out of scope for PCI DSS do not have connectivity into the cardholder data environment (CDE), and that less-secure networks cannot communicate with higher-security networks. Its scope should consider systems considered out of scope in order to verify the effectiveness of segmentation controls used to isolate the CDE from other networks; where such isolation is relied upon to reduce PCI DSS scope, this testing is a means of confirming that the isolation actually holds. Note that the specific PCI DSS requirement numbering, wording, and testing frequency differ between versions of the standard, and readers should confirm the applicable requirements against the current published PCI DSS and its associated Penetration Testing Guidance. This term addresses only the validation of segmentation controls and does not, by itself, assess the security posture of in-scope systems, which is covered by broader application- and network-layer penetration testing.
Why it matters
Segmentation is one of the most common ways organizations reduce PCI DSS scope. By isolating the cardholder data environment (CDE) from the rest of the network, systems that never touch payment card data can be treated as out of scope, which lowers the cost and complexity of compliance. But that scope reduction is only valid if the isolation actually holds. A firewall rule, VLAN, or access control list that is misconfigured, overly permissive, or drifted over time can leave a supposedly out-of-scope network with a path into the CDE. Segmentation penetration testing exists to confirm that the separation relied upon is real rather than assumed.
Without this validation, an organization may believe its scope is smaller than it truly is. If a less-secure network can reach the CDE, then that network is effectively in scope, and controls that should apply to it may be missing. This is where the risk concentrates: an attacker who compromises a low-security segment could pivot into systems handling payment card data if the segmentation gap goes undetected. Segmentation testing is intended to surface these unexpected paths before they can be exploited.
It is important to understand what this testing does and does not cover. Segmentation penetration testing validates the effectiveness of isolation controls; it does not, on its own, assess the security posture of in-scope systems, which is the job of broader application- and network-layer penetration testing. Note also that the specific PCI DSS requirement numbering, wording, and testing frequency differ between versions of the standard, so readers should confirm the applicable requirements against the current published PCI DSS and its associated Penetration Testing Guidance rather than assuming a fixed requirement.
Who it's relevant to
Inside Segmentation Penetration Testing
Common questions
Answers to the questions practitioners most commonly ask about Segmentation Penetration Testing.