API managment for the compliance PCI DSS

Joel Acosta 0 Reputation points
2024-07-09T20:48:14.1733333+00:00
Good afternoon

I am currently advising a company for compliance with the PCI DSS standard in Azure and the following scenario arises. They have an API manager where all the APIs are configured without discrimination, both those that consume and do not consume card data in the Backend. My question is the following, what is the recommended architecture to be able to isolate those APIs that must be part of PCI DSS and separate them from those that are not PCI DSS, or failing that, if it were not necessary to isolate them, so that I can make sure The APIs do not talk to each other and do not have direct communication.

I thank you in advance for your response.
Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
1,918 questions
Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
1,975 questions
Azure Container Apps
Azure Container Apps
An Azure service that provides a general-purpose, serverless container platform.
331 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more