If you have set your variable properly and have a network discovery policy, it's generally not necessary to modify the IPS rules manually - one of the advantages of FirePOWER is that learns your network and adjust the rules accordingly.
You might consider whether to turn on sensitive data detection (a non-default feature) to look for cardholder data leaving the in scope network segments.
http://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Sensitive_Data_Detection.html