Your PCI Scope is Too Big (and how to fix it).
Автор: SecurityMetrics, Inc.
Загружено: 2026-07-21
Просмотров: 52
Описание:
How much of your business actually needs to be PCI compliant? Almost always less than you think.
Every system inside your PCI scope is something you have to secure, document, and prove — year after year. So the fastest way to cut the cost and effort of compliance isn't working harder on controls. It's making your scope smaller.
Principal Security Analysts Jen Stone and Michael Simpson break down how PCI scope actually works: the three buckets every system falls into, the connected systems most people forget, and four practical ways to shrink your Cardholder Data Environment (and the bill that comes with proving it).
WHAT YOU'LL LEARN
What "in scope" really means — and why getting it wrong gets expensive fast
The 3 scoping buckets: primary, secondary (connected), and out of scope
The bucket almost everyone underestimates (hint: your Active Directory)
4 ways to shrink your scope: segmentation, P2PE, tokenization, and fixing phone payments
How taking payments by phone quietly balloons your scope — and the ways out (DTMF masking, IVR handoff, pay-by-link)
Why "we use a third party" and "we're in the cloud" don't get you off the hook
3 costly myths that keep merchants over-scoped and overspending
CHAPTERS
00:00 – Your QSA wants to help you
00:55 – What "scope" actually means
01:34 – First step: find every payment flow
04:17 – "Three Buckets" method for determining scope
04:29 – Bucket 1: Primary Scope
06:04 – Bucket 2: Secondary Scope (the one people miss)
07:23 – Bucket 3: Out of Scope
08:02 – Tip 1: Segment your Network
10:34 – Tip 2: Use P2PE or E2EE
11:41 – Tip 3: Reduce stored credit card data
12:07 – Tip 4: Get phone payments out of scope
12:48 – Third parties: You're still responsible
17:04 – Three scoping myths that could cost you money
19:59 - Where to go for more information
Free PCI Resources
2017 Guide: scoping resources: https://listings.pcisecuritystandards...
2025 Guide: https://blog.pcisecuritystandards.org...
Got a specific scoping question? Leave it in the comments and we’ll get you an answer.
—
SecurityMetrics helps organizations secure payment data and meet PCI DSS. We're a certified PCI Approved Scanning Vendor (ASV), and our employees hold certifications like Certified Information Systems Security Professional (CISSP), PCI Forensic Investigator (PFI), Qualified Security Assessor (QSA), Approved Scanning Vendor (ASV), Payment Application Qualified Security Assessor (PA-QSA), and Point-to-Point Encryption Qualified Security Assessor (P2PE QSA).
#PCIDSS #PCICompliance #PCIScope #ScopeReduction #CardholderData #Segmentation #P2PE #Tokenization #PaymentSecurity #SmallBusinessSecurity #Cybersecurity
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: