What are 'connected-to' systems in PCI DSS scoping?
- A.Only wireless access points
- B.Systems that connect to or communicate with CDE systems but do not directly handle cardholder data
- C.Only monitoring systems, a conclusion v4.0 reaches automatically for any component running a validated payment application, which is descoped without segmentation testing or data-flow analysis
- D.Systems physically near the CDE, which v4.0 waives for facilities protected by a staffed reception desk during business hours
Why B is correct
Connected-to systems communicate with the CDE through network connections or other means but do not directly store, process, or transmit cardholder data. They are in scope because they could impact CDE security.
Know someone studying for PCI DSS? Send them this one.