If you have set your variable properly and have a network discovery policy, it's generally not necessary to modify the IPS rules manually - one of the advantages of FirePOWER is that learns your network and adjust the rules accordingly.
You might consider whether to turn on sensitive data detection (a non-default feature) to look for cardholder data leaving the in scope network segments.