Table of Content - Volume 2 (PCI DSS 4.0.1 edition)


Back to books home

Volume 2 - PCI DSS Scoping (PCI DSS 4.0.1 edition)

  • 2.1 Volume Terminology and Acronyms
  • 2.2 PCI Resources basic diagrams
    • 2.2.1 PCI Resources Base Network Diagram
  • 2.3 Scoping
    • 2.3.1 It all starts with data
  • 2.4 PCI DSS Scoping explained
  • 2.5 PCI Resources Simplified PCI DSS Scoping Model and Approach
    • 2.5.1 Categories Summary
  • 2.6 Simplified Approach and Scoping categories
    • 2.6.1 Simplified Approach Part 1 - CDE (steps 1-3)
    • 2.6.2 Simplified Approach Part 2 - Connected systems (steps 4-6)
    • 2.6.3 Out-of-scope systems
    • 2.6.4 Scope Documentation
    • 2.6.5 Comparison to other models
  • 2.7 Scope Reduction Methods
    • 2.7.1 Outsourcing
    • 2.7.2 Data Reduction (via PAN Transformations)
    • 2.7.3 Segmentation / Isolation
  • 2.8 Advanced Scoping
    • 2.8.1 eCommerce
    • 2.8.2 Card Present payments using Mobile payment devices as terminals
    • 2.8.3 Virtualization and Cloud
    • 2.8.4 Complex Virtualization Cases
    • 2.8.5 Scope of Emails and Instant Messaging Solutions
    • 2.8.6 Scope using genAI/LLM (summer 2026 status)
    • 2.8.7 Non-covered technologies
  • 2.9 Sources and References
  • End Notes - Volume 2
  • Appendix 2A - PCI DSS Scope Documentation Guidance for PCI DSS 4.0 .1