Telnet and other cleartext protocols

Telnet and other cleartext protocols

We Need A Change To 2.3.b (PCI Guru)
I would like to recommend that the Council work to change 2.3.b to take into account the use of network segmentation, firewalls, VLANs, ACLs, MFA and jump boxes to allow the use of Telnet and insecure protocols when in a properly isolated and secure environment. It seems silly to me that someone goes through all of the right steps to secure their environment only to be told that they still need a compensating controls to meet a requirement that does not reflect the real risk.
I am debating this one with a QSA doing an assessment for one of my clients.