Segmentation is one of the most misunderstood aspects of
PCI compliance. Many people read too deeply into the DSS about segmentation. On page 12 of PCI DSS version 4,
1 it states that s
egmentation of the CDE from the remainder of an entity’s network is not a PCI DSS requirement. The next sentence, though, does clarify that segmentation is strongly recommended as ...