What are common methods to reduce PCI DSS scope?
- A.Only using encryption, because the standard defines scope by physical location rather than by data flow
- B.Ignoring certain systems, a conclusion v4.0 reaches automatically for any component running a validated payment application, which is descoped without segmentation testing or data-flow analysis
- C.Reducing the number of employees
- D.Network segmentation, tokenization, P2PE, and outsourcing payment processing to PCI-compliant providers
Why D is correct
Scope reduction methods include network segmentation, tokenization (replacing PANs with tokens), P2PE (encrypting data from the point of interaction), and outsourcing to compliant providers.
Know someone studying for PCI DSS? Send them this one.