PCI Scope Definition
Determine what is in scope through discovery rather than assumption - systems that store, process or transmit account data, plus connected and security-impacting systems - and document the reasoning behind the boundary.
Cardholder Data Environment
Design the CDE deliberately: what belongs inside it, what services it may consume, and what must be excluded, with the aim of keeping the environment as small as it can defensibly be.
Payment Data Flow Mapping
Map every payment flow end to end - channels, integrations, third parties, storage points and support paths - including the flows that exist only for refunds, chargebacks or manual exception handling.
Segmentation Architecture
Design and implement network and access segmentation that meaningfully reduces scope, with the controls and testing needed to demonstrate the separation actually holds.
Secure Configuration
Establish configuration standards for in-scope system components, remove insecure defaults, and implement the change and review process that keeps configurations from drifting.
Identity & Authentication
Implement identity, authentication and multi-factor requirements for access into and within the CDE, including how identity is provisioned, reviewed and removed.
Privileged Access
Control administrative and elevated access with least privilege, separation of duties, session control and the recurring review evidence that validation requires.
Vulnerability Management
Establish the scanning, patching, prioritization and remediation cycle for in-scope components, with the timelines and records needed to demonstrate the process operated continuously.
Logging & Monitoring
Implement logging, retention, review and alerting across in-scope components so that security events are detectable and the review activity itself is evidenced.
Security Testing Governance
Govern the testing programme - internal and external scanning, penetration testing, segmentation testing - including scheduling, scope, remediation tracking and retesting.
Service Provider Management
Identify third parties that affect the security of account data, define responsibility boundaries, and obtain and track the assurance those relationships require.
Compliance Evidence Programme
Build the evidence calendar and record architecture so recurring activities produce durable proof as they happen, rather than being reconstructed at validation.