Can you provide overall system and/or application architecture diagrams including a full description of the data communications architecture for all components of the system?
Explanation
Architecture transparency is what's being requested here, namely diagrams and a full description of the data communications architecture connecting all components of your system.
What it means: The assessor wants to see visual representations (diagrams) of your entire system or application architecture, along with detailed explanations of how data moves through your system. This includes servers, databases, network components, third-party integrations, and any other elements that make up your environment - with special emphasis on components that might process, store, or transmit payment card data.
Why it's being asked: This information helps assessors understand:
- The scope of your PCI DSS environment (what systems are in-scope for compliance)
- Potential security vulnerabilities in your architecture
- How data flows through your system, especially cardholder data
- Whether appropriate security controls exist at critical junctures
- If there are any undocumented or unexpected connections that could pose risks
How to best answer it:
- Provide current, accurate diagrams that show all system components
- Include both high-level overviews and detailed component-specific diagrams
- Clearly mark where cardholder data is stored, processed, or transmitted
- Show all network connections, including those to third parties
- Include security controls like firewalls, encryption points, etc.
- Ensure diagrams are dated and versioned
- Supplement diagrams with written descriptions explaining data flows
- If diagrams contain sensitive information, note that they can be provided under NDA
Example Responses
Example Response 1
Yes, we can provide comprehensive system architecture diagrams for our payment processing application Our documentation includes: (1) A high-level network topology diagram showing all system components including our web servers, application servers, database servers, and connections to payment processors; (2) Detailed data flow diagrams showing how cardholder data moves through our system, with clear marking of encryption points and data storage locations; (3) Network segmentation diagrams showing our PCI DSS scope boundaries and security controls; (4) Written documentation explaining each component and the security measures implemented All diagrams are updated quarterly and include version control These documents can be provided upon request under NDA, as they contain sensitive security information.
Example Response 2
Yes, we maintain detailed architecture documentation for our SaaS platform This includes: (1) Cloud infrastructure diagrams showing our AWS environment with all relevant services (EC2, RDS, S3, etc.) and security groups; (2) Application architecture diagrams detailing our microservices architecture and how each service communicates; (3) Data flow diagrams specifically highlighting the path of payment card information, including tokenization points and which third-party services receive this data; (4) Network segmentation documentation showing how our cardholder data environment is isolated All diagrams use standardized notation (e.g., AWS architecture icons) and include annotations explaining security controls at each layer These documents are reviewed and updated monthly as part of our change management process and can be provided to your assessment team.
Example Response 3
We have some basic network diagrams that our IT team created when the system was initially set up three years ago However, these diagrams haven't been updated to reflect several recent changes to our infrastructure, including our migration to a hybrid cloud environment and the addition of several new payment processing integrations We also don't have specific data flow documentation that tracks how cardholder data moves through our systems Our team is currently working on creating updated documentation, but comprehensive and current architecture diagrams are not available at this time We expect to have updated documentation completed within the next 2-3 months as part of our security improvement initiatives.
Context
- Tab
- Case-Specific
- Category
- Payment Card Industry Data Security Standard (PCI DSS)
Related questions
- Do you have a current, executed within the past year, Attestation of Compliance (AoC) or Report on Compliance (RoC)?
- Is the application listed as an approved Payment Application Data Security Standard (PA-DSS) application?
- Does the system or solutions use a third party to collect, store, process, or transmit cardholder (payment/credit/debt card) data?
- Do your systems or solutions store, process, or transmit cardholder (payment/credit/debt card) data?
- Are you compliant with the Payment Card Industry Data Security Standard (PCI DSS)?
- Are you classified as a service provider?