Deployment Considerations for PCI DSS Compliance

Virtual environments can be PCI compliant and are being deployed throughout the payment card industry in a variety of ways. The PCI DSS applies to all organizations that store, process, or transmit cardholder data, regardless of volume. This includes merchants, service providers, payment gateways, data centers, and outsourced service providers, such as the disaster recovery capabilities provided by Zerto.

This chapter describes recommendations to make Zerto deployment PCI DSS compliant within an already compliant virtual environment. It contains the following sections:

• Zerto in Virtualized Environments
• Questions to Ask to Ensure Compliance With Zerto
• Managing Access Control
• Segmenting the CDE
• Change Control
• Logging and Monitoring
• Managing Zerto at Rest and In Transit
• Conclusion