A regulator asks which systems PCI applies to at a municipal payment processor. What should leadership point to as the durable answer?
Select an answer to reveal the explanation.
Short Explanation
When a regulator asks “which systems?”, “trust us” is not an artifact. A documented PCI entity scope—the named apps and services in that bubble—is the answer you can hand over. Scope turns applicability into a list, not a hallway promise.
Full Explanation
Regulatory applicability is operationalized as a defined entity population for the relevant program or policy. Documented PCI scope identifies which systems, networks, and services fall under that obligation and become targets for controls and evidence. Verbal promises and unfiltered “everything” claims fail audits. Entity associations make applicability reportable and maintainable as the environment changes.