🎓 CoursesMarkets & internationalAdvanced⏱ 60 min

Protecting payment data across borders. 6 chapters and a final quiz.

Managing payment data for a company that operates across continents. Define the PCI DSS scope and shrink it, choose between vault tokens and network tokens, and apply the Indian, Chinese, and Indonesian localization regimes without mixing them up. Pick the GDPR Chapter V transfer instrument, build a country-by-country retention matrix, then produce the evidence a Qualified Security Assessor asks for.

Chapter 1. Defining the scope before protecting it.

A security standard is demonstrated against a written scope: without one, no requirement applies to anything. PCI DSS calls this scope the CDE, the cardholder data environment, and defines it as the people, processes, and systems that store, process, or transmit account data. It also includes any connected system that could compromise them. That second half of the definition tends to get lost.

Three categories, not two

  • Inside the CDE: the system sees, stores, or carries account data. Application servers, message buses, call recorders.
  • Connected or security-impacting: the system does not see the data but can put it at risk. Identity directories, jump servers, hypervisor consoles, deployment pipelines.
  • Out of scope: no access, no influence, and isolation demonstrated by testing. Isolation must be proven; it cannot simply be declared.
ScenarioCategoryWhat the assessor asks for
Back office shows a masked PAN from a tokenized databaseInside the CDE if the detokenization service is reachable from that serverFirewall rules to the vault and the access rights matrix
The identity provider authenticates CDE administratorsSecurity-impactingAdmin access boundary, multi-factor authentication, privileged-account logging
The deployment pipeline pushes code to CDE serversSecurity-impactingPipeline controls, code review, separation of secrets
The call center records calls in which customers read out their card detailsInside the CDEPause-and-resume recording, CVV purge, access logs for recordings
The marketing website, on a separate network with no route to the CDEOut of scopeDated penetration test of the segmentation controls
What brings a system into scope

A multi-country business does not have one CDE. It has one per regional stack. A localization obligation creates a local stack, with its own servers, administrators, and backups, and that stack comes into scope like the others. The classic mistake is to describe the target architecture at headquarters and ignore the local deployments that local law requires.

Searching for stray PAN where the data should not be
# PAN candidates: Visa, Mastercard, Amex, Discover.
# A regex is not enough: filter the hits with a Luhn check.
PAN='\b(4[0-9]{12}([0-9]{3})?|5[1-5][0-9]{14}|3[47][0-9]{13}|6(011|5[0-9]{2})[0-9]{12})\b'

# Application logs, exports, backups mounted read-only.
grep -rInE "$PAN" /var/log /srv/exports /mnt/backup \
  --exclude-dir=.git -l > /tmp/locations.txt

# NEVER log the matched value: only the path and the line count.
# The list of locations is itself sensitive data: it lives in the CDE.
⚠️
Scope drifts between audits
PAN resurfaces where nobody expects it: in an emergency export, a debug table, a message queue that was never purged. Since March 31, 2025, PCI DSS v4.0.1 has required a response procedure for PAN found outside its expected locations (requirement 12.10.7). Finding PAN is not the incident. Having no procedure is.
March 31, 2025
date the future-dated requirements of PCI DSS v4.x became mandatory
PCI Security Standards Council
12 months
how often scope must be confirmed in writing; every 6 months for a service provider
PCI DSS v4.0.1, requirements 12.5.2 and 12.5.2.1
3 months
how often to verify that account data past its retention period has been deleted
PCI DSS v4.0.1, requirement 3.2.1
🎯 Quick question
Your identity directory, hosted outside the CDE, authenticates the payment servers’ administrators. Which scope category does it fall into?