Document Metadata & Governance
- Document Owner: Cybersecurity & Infrastructure Operations Units
- Compliance Alignment: PCI DSS v4.0.1 (Req 12.8.5, 12.9.1, 12.9.2), ISO/IEC 27001:2022 (A.5.19-5.22), ISO/IEC 27017:2021 (CLD.6.3.1)
- Service Scope: Layer3Cloud IaaS, Multi-Tenant Hypervisor Platform, SAN Storage, Virtual Data Center (vDC), and Core Physical Network Fabric
- Effective Date: August 2026
- Target Audience: Layer3Cloud Enterprise Tenants, Qualified Security Assessors (QSAs), Internal Compliance Auditors
1. Executive Summary & Purpose
As a Cloud Service Provider (CSP) delivering Infrastructure as a Service (IaaS) and Virtual Private Data Center (vDC) solutions, Layer3Cloud operates as a Third-Party Service Provider (TPSPA) under PCI DSS v4.0.1 guidelines. While Layer3Cloud does not store, process, or transmit Cardholder Data (CHD) or Sensitive Authentication Data (SAD) on behalf of its clients, Layer3Cloud provisions and maintains the underlying physical, network, and virtualization infrastructure that hosts tenant Cardholder Data Environments (CDE).
This Shared Responsibility Matrix formally outlines the division of security obligations between Layer3Cloud and its enterprise tenants to ensure complete coverage of all PCI DSS v4.0.1 requirements.
2. Control Allocation Models
Security controls within the Layer3Cloud ecosystem are categorized into three distinct execution models:
- Layer3Cloud Managed (Service Provider): Layer3Cloud maintains sole operational responsibility for the design, configuration, monitoring, and physical/logical security of the underlying infrastructure.
- Customer Managed (Tenant): The tenant maintains sole responsibility for the security, configuration, and administration of hosted virtual assets, guest operating systems, applications, and data layers.
- Shared / Collaborative: Both Layer3Cloud and the tenant maintain distinct responsibilities within the control domain. Layer3Cloud provides secure, isolated infrastructure tools, while the tenant must properly configure, enforce, and audit the control within their virtual environment.
3. Comprehensive PCI DSS v4.0.1 Responsibility Allocation
| PCI DSS Domain | Allocation | Layer3Cloud Responsibility | Customer / Tenant Responsibility |
|---|---|---|---|
| Req 1: Network Security Controls | Shared | Manages physical perimeter edge routers, core switches, physical firewall access lists, hypervisor-level micro-segmentation (VXLAN/VLAN isolation), infrastructure anti-DDoS, and conducts multi-tenant segmentation testing. | Configures guest OS software firewalls, virtual security groups, routing tables within vDCs, and restricts inbound/outbound application traffic for hosted workloads. |
| Req 2: Secure Configurations | Shared | Maintains hardening baselines (CIS Benchmarks) for bare-metal hypervisors, SAN storage, core switch firmware, and cloud orchestration management interfaces. Removes vendor defaults across physical gear. | Hardens guest operating system instances, disables unnecessary OS services/ports, updates default credentials for custom or commercial software, and maintains guest templates. |
| Req 3: Account Data Protection | Shared | Enforces physical storage array security and executes certified physical disk destruction/sanitization protocols for decommissioned or failed storage drives. | Encrypts application-level cardholder databases, manages cryptographic keys, defines data retention/purge policies inside guest VMs, and implements field-level truncation. |
| Req 4: Encryption in Transit | Shared | Protects physical fiber interconnects between data center nodes and enforces TLS 1.2+ encryption across Layer3Cloud administrative management web portals and APIs. | Configures application-layer TLS 1.2/1.3 parameters, secure web server certificates, and encrypted VPN tunnels for data moving into or between tenant virtual machines. |
| Req 5: Malware Protection | Customer | Deploys EDR/Anti-Malware agents (SentinelOne) strictly across Layer3Cloud infrastructure control plane servers, hypervisor management hosts, and administrative jump boxes. | Procures, installs, configures, and monitors antivirus/EDR software inside all guest operating system instances hosted within their vDC. |
| Req 6: Secure Systems & Software | Shared | Applies vendor security patches to bare-metal hypervisors, SAN storage controllers, and physical network gear within 30 days of release. Enforces secure SDLC for cloud portal development. | Patches guest operating systems, database engines, web servers, and third-party software, and maintains secure software development practices for custom hosted apps. |
| Req 7: Access Restrictions | Shared | Enforces Role-Based Access Control (RBAC) and least privilege for Layer3Cloud personnel accessing backend cloud hypervisors and physical infrastructure. | Defines and manages user access privileges, RBAC rules, and access control lists for guest OS logins, databases, and application software. |
| Req 8: Authentication & MFA | Shared | Enforces unique user IDs and mandatory Multi-Factor Authentication (MFA) for all Layer3Cloud administrative access to hypervisor planes, physical switches, and cloud portals. | Enforces MFA, password complexity, user offboarding, and unique account management for all tenant administrative users accessing guest OS instances and applications. Ensures unique credentials per client. |
| Req 9: Physical Security | Layer3Cloud | Maintains physical perimeter security, biometric/badge access control, 24/7 CCTV surveillance with 90+ day log retention, visitor logging, and physical protection of data center facilities. | Secures physical client office premises, employee workstations, remote access endpoints, and on-premise local network infrastructure connecting to Layer3Cloud. |
| Req 10: Logging & Monitoring | Shared | Aggregates physical switch, hypervisor API, and network syslog data into centralized log management (Security Onion), maintaining 12-month retention and daily operational log reviews. | Collects, reviews, and retains audit logs from guest operating systems, applications, and virtual firewalls into a tenant SIEM repository for 12 months. |
| Req 11: Security Testing | Shared | Executes bi-annual hypervisor segmentation testing, infrastructure ASV external vulnerability scans, and annual network-layer penetration testing covering the cloud fabric. | Conducts quarterly authenticated internal vulnerability scans, quarterly ASV external scans, and annual application/network penetration tests against tenant-hosted IP targets. |
| Req 12: Information Security | Shared | Maintains organizational Information Security Policies, conducts background checks on infrastructure engineers, maintains PCI DSS Attestation of Compliance (AOC), and provides TPSPA support. | Establishes internal security policies, risk assessments, employee security awareness training, incident response plans, and regulatory compliance reporting for tenant workloads. |
4. Formal Service Provider Acknowledgment (Requirement 12.9.1)
Formal Written Acknowledgment Statement:
Layer3Cloud formally acknowledges responsibility for the security of the physical, network, and virtualization infrastructure supporting tenant Virtual Private Data Centers (vDC) to the extent that Layer3Cloud impacts the security of the customer's Cardholder Data Environment (CDE).
Layer3Cloud maintains compliance with PCI DSS v4.0.1 as a Service Provider for the infrastructure scope detailed herein and provides annual Attestations of Compliance (AOC) to enterprise clients upon request to support their independent compliance validation.
5. Audit Evidence & Attestation Requests
Enterprise tenants undergoing PCI DSS assessments may request the following verification artifacts from Layer3Cloud Compliance Operations:
- Layer3Cloud Official Attestation of Compliance (AOC) for Service Providers.
- Summary Report of Multi-Tenant Network Segmentation Testing.
- Executive Summary of Annual Infrastructure Network Penetration Testing.
- Data Center Physical Security & Environmental Audit Summary.