As of right now, my organization is PCI DSS complaint but we learned that it's a big no-no if we tried to mix in-scope and out-of-scope systems. We also saw that PCI leaders said this regarding scopes in a virtual environment.
The level of segmentation required for in-scope and out-of-scope systems on the same host must be equivalent to a level of isolation achievable in the physical world; that is, segmentation must ensure that out-of-scope workloads or components cannot be used to access an in-scope component. Unlike separate physical systems, network-based segmentation alone cannot isolate in-scope from out-of-scope components in a virtual environment.
So here's the big question: Can we segment VMs that are running on ESXi so the segmentation satisfies that statement?
Free Guide: Managing storage for virtual environments
Complete a brief survey to get a complimentary 70-page whitepaper featuring the best methods and solutions for your virtual environment, as well as hypervisor-specific management advice from TechTarget experts. Don’t miss out on this exclusive content!