Deployment Considerations for PCI DSS Compliance

Virtual environments can be PCI compliant and are being deployed throughout the payment card industry in a variety of ways. The PCI DSS applies to all organizations that store, process, or transmit cardholder data, regardless of volume. This includes merchants, service providers, payment gateways, data centers, and outsourced service providers, such as the disaster recovery capabilities provided by Zerto.

This chapter describes recommendations to make Zerto deployment PCI DSS compliant within an already compliant virtual environment. It contains the following sections:

Zerto in Virtualized Environments
Questions to Ask to Ensure Compliance With Zerto
Managing Access Control
Segmenting the CDE
Change Control
Logging and Monitoring
Managing Zerto at Rest and In Transit
Conclusion