simpl.
Cybersecurity GRC 12 items

PCI DSS 4.0 Network Segmentation Verification

Verifies that segmentation controls effectively isolate the cardholder data environment (CDE) to reduce PCI DSS scope.

PCI DSS 4.0

Free PDF · enter your email to download.

Scope & CDE Definition

  • Is the cardholder data environment (CDE) boundary documented and current? *
  • Is a data-flow diagram maintained showing all account data flows across systems? *
  • Are connected-to and security-impacting systems identified within scope? *

Segmentation Controls

  • Do network security controls isolate the CDE from out-of-scope networks? *
  • Is inbound and outbound traffic to the CDE restricted to only what is necessary? *
  • Are private IP addresses and routing disclosure to untrusted networks restricted? *

Firewall & Ruleset Management

  • Are firewall and router rulesets reviewed at least every six months? *
  • Is a default deny-all posture enforced with only explicitly authorized rules? *
  • Are configuration standards for network security controls documented? *

Segmentation Testing

  • Is segmentation penetration testing performed at least annually (or every 6 months for service providers)? *
  • Do test results confirm segmentation is operational and isolates the CDE? *
  • When was the most recent segmentation test completed?

Download the full PCI DSS 4.0 Network Segmentation Verification checklist

Get it as a clean, printable PDF — free.