Open PCI Scoping Toolkit

A Structured Method for Determining Which System Components in an Organization’s Computing Environment Are Within the Scope of Assessment

Successful PCI DSS compliance depends upon the correct identification of the scope of the assessment. An overly narrow scope can jeopardize cardholder data, while an overly broad scope can add unnecessary cost and effort to the PCI compliance program. Subjective interpretation of the PCI DSS guidance results in a wide variance in practice among both QSAs and Participating Organizations.

The Toolkit consists of definitions, three scoping categories, a decision tree and illustrative scoping scenarios. The Toolkit helps organizations and assessors determine correct scope of assessment, provides a common framework to discuss risks to cardholder data and facilitates discussion of controls, and is intended to be consistent with the spirit and intent of the PCI DSS.

This document includes the following sections:

Definitions – provides definitions of terms used in this document and within the PCI DSS, and describes the expansion or clarification of those terms proposed by the Toolkit.

Categorization of System Components – defines the characteristics of system component categories defined by the Toolkit and lists the implications of each.

Scoping Decision Tree – diagrams each step in the decision process and lists the criteria for each decision.

Scoping Scenarios – provides illustrative examples of typical situations found in organizations’ environments and shows how each system component would be categorized using the scoping decision tree.

Although addressing the people and processes around cardholder data is a necessary part of any PCI compliance program, the Toolkit focuses almost entirely on categorizing the system components that comprise an organization’s computing environment.

In addition, the Toolkit does not define what PCI DSS controls are required for each Toolkit category. Because every organization is different, it is up to each organization and its assessor to determine the nature, extent and effectiveness of each control to adequately mitigate the risks to cardholder data.

We want to acknowledge the hard work of the forty-seven other practitioners who have contributed to this work since March 2009. We eagerly look forward to the time when all of these individuals can be publicly recognized for their contribution to this work.

What's inside

  • Determination — Aids in determination of which system components are in and out of the scope of assessment.
  • Common Language — Facilitates communication between organizations and assessors by providing a common language to describe the computing environment and risks to cardholder data.
  • Framework — Provides a framework to categorize and identify the different types of system components, each with a different risk profile associated with it.
  • Reduction of Scope — Provides a thought process to reduce the scope of assessment, by isolating and controlling access to the CDE, re-architecting the control environment or by implementing further controls.
Definitions
Provides definitions of terms used in this document and within the PCI DSS, and describes the expansion or clarification of those terms proposed by the Toolkit.
Categorization of System Components
Defines the characteristics of system component categories defined by the Toolkit and lists the implications of each.
Scoping Decision Tree
Diagrams each step in the decision process and lists the criteria for each decision.
Scoping Scenarios
Provides illustrative examples of typical situations found in organizations’ environments and shows how each system component would be categorized using the scoping decision tree.
Topics
Audit & Security
Formats
pdf
License
Creative Commons BY-NC-SA

About the authors

4 authors
Dorian CougiasCo-Founder and CEO, Unified Compliance Framework

Dorian J. Cougias is the Lead Analyst of the Unified Compliance Framework (UCF) and co-founder of Network Frontiers (dba Unified Compliance), a company focusing on the science of compliance, including harmonization methods, metrics, systems continuity, and governance. Over the last sixteen years, Dorian has overseen the establishment, sale, and re-launch of Network Frontiers, has served as CIO of two of the leading advertising agencies in the world, and has served as CEO of an international software company. He has written and spoken extensively on all matters of information technology, is a leading expert witness, and has won numerous writing and speaking awards. Dorian serves as an adviser or working group member to the Payment Card Security Council, Financial Technology Forum, and other industry organizations. He is also an Emeritus Professor of Technology, lecturing and serving on the board of advisers for the University of Delaware; College of Human Services, Education, and Public Policy. As the primary architect of the Unified Compliance Framework® (UCF), Dorian and his research partner, Marcelo Halpern of the international law firm, Perkins Coie, have created the first and largest data structure and repository of regulatory compliance content for governance, risk and compliance (GRC) management. The UCF (and its Software-as-a-Service portal the Common Controls Hub) provide a structure, a methodology, and the evidence needed to prove compliance, allowing companies to easily and transparently accelerate their IT compliance and governance.

Everything by Dorian Cougias →

Phil Cox
Gene KimFounder, Author, Researcher, IT Revolution

Gene Kim has been studying high-performing technology organizations since 1999. He was the founder and CTO of Tripwire, Inc., an enterprise security software company, where he served for 13 years. His books have sold over 1 million copies—he is the WSJ bestselling author of The Unicorn Project and The Phoenix Project Graphic Novels , and co-author of The Phoenix Project , The DevOps Handbook , Vibe Coding , and the Shingo Publication Award-winning books Accelerate and Wiring the Winning Organization . Since 2014, he has been the organizer of DevOps Enterprise Summit (now Enterprise Technology Leadership Summit and Enterprise AI Summit), studying the technology transformations of large, complex organizations.

Everything by Gene Kim →

Ruth XovoxExoIS

Strong leadership, excellent communication skills, attention to detail, and a thorough knowledge of current global security and privacy regulations.

Everything by Ruth Xovox →