essay · pci-dss-active-defense
Threxen resources

PCI-DSS active defense

A cornerstone for the cardholder data environment: how Threxen’s PCI-DSS 4.0-aligned tenants segment the CDE, bind every containment action to a numbered requirement, and produce the audit-ready evidence an acquirer or QSA can review.

PCI-DSS v4.0 ships twelve principal requirements and the A3 Appendix for entities that store sensitive authentication data. Requirements 1 and 2 lay out network security controls and the configuration of those controls; Requirement 3 governs stored account data; Requirement 4 covers transmission security; Requirements 6 and 11 set development and test discipline together with the testing cadence; Requirement 8 is identity; Requirement 9 covers physical access; Requirement 10 is the logging obligation; Requirement 11 is the testing schedule; Requirement 12 sets the operational policy. A Threxen tenant pinned to the PCI-DSS pack under /app/settings/policy cites Req. 1.2 to express one-line containment, Req. 8.4 to enforce MFA across the CDE, and Req. 10.2/12.10 to bind every containment packet to a numbered requirement the auditor can look up.

The cardholder data environment is the perimeter; outside-of-it is the perimeter too. CDE segmentation is what Requirement 1 no longer carves by exception: every system that stores, processes, or transmits cardholder data lives inside the boundary, and the key envelope is what ensures adjacent PCI tenants cannot read each other’s data — rotation, escrow, and BYOK are first-class and exercised end-to-end before a tenant flips to production. Decoys are live-poisoned the moment an actor touches them, the rendered surface fakes SAD under Req. 3.5, and the credential poisoning invalidates the captured cred at the IdP under Req. 8.5 rather than at the CDE perimeter.

Active-defense containment under PCI-DSS reduces to three mapped requirements the QSA can check on the trust page at /trust: Req. 11.5 intrusion detection, Req. 6.4 application-layer controls for public-facing services, and Req. 12.10 incident response. The numbering is the proof. Nothing in active defense crosses the boundary the QSA did not draw, and the audit log is the only artifact the QSA reads — the rest is drift-free by construction. See /resources/sector-coverage for the full control-by-control matrix.

All resourcessecurity & compliance posture →Threxen · static essay · drift-free by construction
compare across all five frameworks

Read this regulator alongside its four peers.

The same four capabilities — host isolation, live credential poisoning, decoy surface, and the hash-chained evidence packet — are mapped onto each named article, requirement, or control of every regulated framework Threxen ships a policy pack for. The comparison matrix is the single page that lays them side by side.

▸ four sibling pillars · one matrix page · biometric-style read-across without re-reading five essays · security & compliance posture on the trust center