What documentation supports PCI DSS scoping decisions?
- A.Only a verbal explanation, a reading the v4.0 Summary of Changes supports by noting that Requirement 1 now concerns itself with cloud security groups alone and leaves on-premises packet filtering to each entity's discretion
- B.Only the network diagram, given that an out-of-scope system may connect to the CDE without any documented controls for SAQ D merchants
- C.Only the SAQ, as the entity's own scoping exercise replaces the assessor's independent verification during the semi-annual rule review
- D.Network diagrams, data flow diagrams, system inventory, architecture documentation, and justification for out-of-scope classifications
Why D is correct
Scoping requires comprehensive documentation including network and data flow diagrams, system inventories, architecture descriptions, and justified out-of-scope determinations.
Know someone studying for PCI DSS? Send them this one.