Disaster-recovery obligations cover different systems than the city’s PCI scope. How should entity scoping handle that?
Select an answer to reveal the explanation.
Short Explanation
PCI cares about card data paths; disaster recovery cares about what must survive an outage—those circles overlap but are not twins. Let each program keep its own entity scope instead of mashing them into one giant blob. Multiple scopes keep obligations honest.
Full Explanation
Different GRC programs often require different applicability. Entity framework supports scoping content and activities to the populations relevant to each obligation. Collapsing unrelated programs into one mega-scope either over-tests systems or under-covers critical recovery targets. Separate, purpose-driven scopes preserve accuracy while still reusing shared entity master data where overlap exists.