Network segmentation and optimizing your validation for PCI DSS

By Yozer Esneider Garcia Marulanda

Elevator Pitch

Verifying a segmented environment can be inefficient. The use of automation is a big help to the analyst. So, the script I developed “El Segmentador” provides the analyst with an easy and fast method of performing the segmentation test, allowing more time to perform a better analysis of the results

Description

Implementing network segmentation is necessary because it brings several benefits to corporate networks, such as facilitating administration and control, improving performance, containing horizontal spread of threats, minimizing asset risks and reducing the effort required during audits.

In addition to implementing network segmentation, it is recommended that a thorough check be performed to ensure that all network configuration is as planned to ensure communication of the means that make sense for business applications.

As the verification process can be very slow and difficult to automate, using “El Segmentador” minimizes manual tasks and time spent by analysts, allowing them to focus more closely on analyzing the results obtained.

Notes

I feel prepared to present this conference for the experience gained in my academic and professional career, which allowed me to work to answer the recurring difficulty of validating the implementation of network segmentation of the company in which I work and its subsequent presentation to the PCI DSS report. This process culminated in the development of the automation script “El Segmentador”. By working directly with him and knowing his deep usage I find myself able to know the best way to share this information with viewers.