Segmentation
Now that you know what subnetting is, let’s discuss segmentation. PCI-DSS specifically requires that the CDE is segmented from the rest of the network. Segmentation is enforced with firewall rules. Firewalls are used to control the traffic that is allowed to enter or leave each segment, based on defined firewall rules. Segmentation is an advanced way to ensure that simply because a hacker is on your network, they won’t be able to gain access to a critical asset or, even more importantly, critical data on a segmented subnet. You can segment a subnet from the regular network using a firewall. It’s not a simple task because you have to evaluate all of the traffic traversing your firewall to ensure you segment only specific subnets. Segmentation is not only an important safeguard for critical assets but will also protect your network from easily hacked Internet of Things (IoT) devices. Segmenting your IoT devices ensures they are separated from your regular...