Back to books home
Volume 2 - PCI DSS Scoping (PCI DSS 4.0.1 edition)
- 2.1 Volume Terminology and Acronyms
- 2.2 PCI Resources basic diagrams
- 2.2.1 PCI Resources Base Network Diagram
- 2.3 Scoping
- 2.3.1 It all starts with data
- 2.4 PCI DSS Scoping explained
- 2.5 PCI Resources Simplified PCI DSS Scoping Model and Approach
- 2.5.1 Categories Summary
- 2.6 Simplified Approach and Scoping categories
- 2.6.1 Simplified Approach Part 1 - CDE (steps 1-3)
- 2.6.2 Simplified Approach Part 2 - Connected systems (steps 4-6)
- 2.6.3 Out-of-scope systems
- 2.6.4 Scope Documentation
- 2.6.5 Comparison to other models
- 2.7 Scope Reduction Methods
- 2.7.1 Outsourcing
- 2.7.2 Data Reduction (via PAN Transformations)
- 2.7.3 Segmentation / Isolation
- 2.8 Advanced Scoping
- 2.8.1 eCommerce
- 2.8.2 Card Present payments using Mobile payment devices as terminals
- 2.8.3 Virtualization and Cloud
- 2.8.4 Complex Virtualization Cases
- 2.8.5 Scope of Emails and Instant Messaging Solutions
- 2.8.6 Scope using genAI/LLM (summer 2026 status)
- 2.8.7 Non-covered technologies
- 2.9 Sources and References
- End Notes - Volume 2
- Appendix 2A - PCI DSS Scope Documentation Guidance for PCI DSS 4.0 .1