100% VERIFIED.
Scoping Review
Systems Providing Security Services - ANS Systems providing security services as required by
PCI DSS, or that may be contributing to how an entity meets PCI DSS requirements may include:
-Authentication servers (e.g. LDAP)
-Time management (e.g. NTP) servers
-Patch deployment servers
-Audit log storage and correlation servers
-Anti-virus management servers
-Routers and firewalls filtering network traffic
-Systems performing cryptographic and/or key management functions
-Systems controlling and/or monitoring physical access
PCI DSS scope includes: - ANS -People
-Processes
-Technology
Scoping: People - ANS Examples of roles that may be included in scope of assessment:
COPYRIGHT © 2025 THESTAR ALL RIGHTS RESERVED 1
,-Cashiers and sales clerks
-Back-office clerks
-Call center operators
-Systems and network administrators
-IT support personnel
-Application developers
-Key custodians
-Human resources
-Information security officers
-Physical security officers
-Customer support
-Accounting/finance personnel
-Supervisors/managers for each area
-Senior management and executives
Scoping: Processes - ANS Examples of processes related to payment processing:
-Regular payment processing channels
-Payment cancellations and chargebacks
-Back-up and fail-over processes
-Reconciliation, periodic reporting
-Distribution and storage of paper reports and other physical media
-Legacy processes and data stores
-Onboarding processes for new personnel
Examples of supporting processes:
-Authorizations and approvals for system access
-Firewall review processes
COPYRIGHT © 2025 THESTAR ALL RIGHTS RESERVED 2
,-Change management
-Scheduling of security patch deployments
-System building and configuration
-Identifying and escorting visitors
-Performing log reviews
-Processes for reporting potential security incidents
-Security policy updates
Scoping: Technology - ANS Examples of types of technologies:
-Servers, applications, networks, devices
-Physical security systems
-Logical security systems
-Payment terminals and point of sale systems
-Electronic communications
-Backups and disaster recovery "hot" sites
-Telecommunications: POTS vs. VoIP
-Management systems
-Remote access systems
Sampling - ANS Sampling is an option for assessors to facilitate the assessment process.
- Sampling is NOT used to implement PCI DSS requirements or to select
requirements to be assessed
Principles of sampling:
- Sample must be representative of the entire population
COPYRIGHT © 2025 THESTAR ALL RIGHTS RESERVED 3
, - Consider business facilities and system components
- Samples of system components must include all combinations
- Samples must be large enough to provide assurance that controls are implemented as
expected
- Assessor's sampling methodology documented in ROC
Planning for the Assessment - ANS Pre-assessment planning may include:
-List of interviewees, system components, documentation, facilities
-Ensure assessor is familiar with technologies included in assessment
-If sampling, verify sample selection and size is representative of the entire population
-Identify the roles and the individuals within each role to be interviewed as part of the
assessment
Sampling Scenario - ANS What to consider?
-What are the different OS/database combinations at each facility?
-Is each OS/database combination used for the same purpose?
-Is each OS/database combination configured the same way?
-If they are configured the same way, how is this verified?
-Do the different locations follow one single set of operational and security procedures, or do
they each have their own?
-If they follow the same procedures, how is this verified?
-Which facilities/components were reviewed in the previous assessment?
Sampling is not just about technology
Assessment Time and Duration - ANS Allow enough time to perform the assessment
COPYRIGHT © 2025 THESTAR ALL RIGHTS RESERVED 4