Jul 16, 2026

PCI DSS Scoping

In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:     

  • When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is made
  • Whether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessment
  • Why Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scoping
  • Some examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scope
  • How elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scoping
  • And more.

Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping        

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts         

Connect with us on LinkedIn 

Brought to you by URM, the UK’s leading information and cyber security specialists.   

Comment (0)

No comments yet. Be the first to say something!

Copyright 2024 URM Consulting. All rights reserved.

Podcast Powered By Podbean

Version: 20241125