How do you demonstrate PCI Compliance 11.3 compliance (segmentation) using SOA/web services? (Apigee, F5, Layer 7, Crosscheck)

SMBIT
SMBIT used Ask the Experts™
on
How do you demonstrate PCI Compliance 11.3 compliance (segmentation) using SOA/web services? (Apigee, F5, Layer 7, Crosscheck) I do not need specific instructions for any particular solution (but it might help)  just a high level overview or the process and what questions to ask.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Fractional CTO
Distinguished Expert 2018
Commented:
You can't really do this generically.

Each PCI Scanning service implements a different set of scans + procedure for scanner to access a system, usually using sftp + ssh access.

You can only demonstrate passing one scanner service. If you then use another scanner service, likely the scan will fail till some other system changes are made.

Notice I said changes, rather than fixing problems, as many scanners provide... less than useful failures, which have no real effect on security.

The game with PCI compliance, is to pass the scanner services foisted on you by some other agency, like a merchant card processor.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial