PCI Compliance | Network PCI DSS Compliance Requirements Testing | RedSeal
RedSeal
  • Platform
    • RedSeal Platform
    • Solutions
      • Network Visualization
      • Compliance
      • Risk Prioritization
    • CTEM
    • Integrations
  • Services
    • CTEM
    • Professional Services
    • Customer Support
    • RedSeal University
    • Remote Workforce
  • Industries
  • Partners
    • RedSeal Partners
    • Partner Portal
  • Company
    • About RedSeal
    • Leadership
    • Careers
  • Resources
    • Blog
    • Events
    • Resource Center
  • Contact Us
  • GET A DEMO
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
List List Menu
  • DoD
  • Civilian
  • Intelligence
  • State and Local
  • Solutions
    • What is Network Visualization and Continuous Monitoring?
    • Risk and Vulnerability Management
    • STIG and SRG Compliance and Reporting
    • Risk Scoring and Incident Response
    • Cloud Security
    • PCI Compliance
    • NIST 800-53
    • Cyber Protection Teams (CPT)
    • How to Buy
  • Partners
  • Resources

PCI Compliance

Meet PCI compliance with efficiency.

The Payment Card Industry Data Security Standard (PCI DSS) includes a number of controls that pertain to network architecture, configuration, and operations. RedSeal’s unique ability to map your network, calculate potential access, and prioritize risk is well suited for compliance with many network PCI DSS requirements, especially those related to firewalling, network segmentation, and penetration testing.

RedSeal also helps organizations meet the “Business as Usual” best practices in PCI DSS 3.2. The PCI DSS BAU guidelines were added to emphasize the need to implement security controls as ongoing processes, rather than focusing on “just in time” PCI compliance requirements when the annual audit rolls around. RedSeal analyzes network infrastructure and risk on a nightly basis. This allows an organization to implement continuous monitoring of their segmentation and network firewall configuration and effectiveness, with minimal operational overhead.

RedSeal helps your network meet PCI DSS compliance requirements by monitoring and managing all PCI DSS specific network requirements.

  • PCI DSS Compliance Requirement 1—Firewall Configuration

    Current network diagram; firewall and DMZ architecture validation.

  • PCI DSS Compliance Requirement 2—Configuration Hardening

    Configuration best practices and default removal for network and firewall infrastructure.

  • PCI DSS Compliance Requirement 6—Secure Systems

    Determine risk ranking for network vulnerabilities based on severity, frequency and exposure.

  • PCI DSS Compliance Requirement 11.3—Penetration Testing

    Re-testing of network segmentation following changes; prioritization and remediation of exploitable vulnerabilities.

  •  PCI Compliance Network Requirements—Segmentation

    Validation of segmentation boundary; includes support for “Category 1/2/3” best practice segmentation strategy rapidly gaining traction with QSAs (Qualified Security Assessors). For more detail on RedSeal mapping to PCI 3.2 controls:

    How RedSeal Helps your Network meet PCI DSS Compliance Requirements
  • PCI DSS Compliance Requirement 11.3.4—Penetration Testing and CDE Segmentation

    A great example of how PCI DSS 3.0 significantly changes control activity implementation is the new requirement for penetration testing of the CDE segmentation boundary (11.3.4).

This PCI compliance network requirement states that penetration testing must be done “…after any changes to segmentation controls/methods to verify that the segmentation methods are operational and effective, and isolate all out-of-scope systems from in-scope systems.”  In practice, this could be interpreted to mean that pen testing needs to be done after any firewall rule or ACL change on any device that segments the CDE—a massive undertaking. However, RedSeal can continually test the segmentation boundary and identify those portions of the boundary that actually changed, allowing pen testing to be focused on just those elements. This drastically reduces the cost and effort required to meet this stringent new requirement. For more information, download our white paper: CDE Segmentation Validation.

Government Solutions

  • What is Network Visualization and Continuous Monitoring?
  • Risk and Vulnerability Management
  • STIG and SRG Compliance and Reporting
  • Risk Scoring and Incident Response
  • Cloud Security
  • PCI Compliance
  • NIST 800-53
  • Supporting Cyber Protection Teams (CPT)
  • How to Buy

Get the latest news, invites to events, and threat alerts

Platform

  • RedSeal Platform
  • Solutions
  • CTEM
  • Integrations

Services

  • CTEM
  • Professional Services
  • Customer Support
  • RedSeal University
  • Remote Workforce

Government

  • DoD
  • Civilian
  • Intelligence
  • State and Local
  • Government Solutions
  • Government Partners
  • Government Resources

Partners

  • Commercial Partners
  • Government Partners
  • EMEA Distributors
  • MSSP Partners
  • Technology Integration Partners
  • Partner Portal

Company

  • About RedSeal
  • Leadership
  • Careers

Resources

  • Blog
  • Events
  • Resource Center
CONTACT US
RedSeal Japan
Distinguished Vendor badge 2025

© Copyright by RedSeal, Inc. All Rights Reserved.
  • Link to X
  • Link to LinkedIn
  • Link to Youtube
  • Link to Rss this site
  • Standard Agreements
  • Terms of Use
  • Privacy Policy
  • Section 508 Policy
Scroll to top Scroll to top Scroll to top

In order to provide you with the best experience possible we might sometimes track information about you. Sometimes this may involve writing a cookie. We use this information for things like experience enrichment, analytics and targeting advertising. We recommend allowing these functions to get the most out of your experience.

OK

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Accept settingsHide notification only
Footer
Connect on LinkedIn