What happens to PCI DSS scope if an organization does NOT implement network segmentation?
- A.Only the payment application is in scope, since components that only transmit encrypted cardholder data are automatically out of scope without further analysis
- B.Only servers storing cardholder data are in scope, because a flat network keeps the assessment simpler and is the design the SSC formally recommends
- C.The entire network and all connected system components are considered in scope for PCI DSS assessment
- D.Nothing changes; scope remains minimal
Why C is correct
Without network segmentation, PCI DSS scope extends to the entire network, meaning all system components must be assessed and comply with applicable PCI DSS requirements.
Know someone studying for PCI DSS? Send them this one.