Practical Cybersecurity with Jen Stone
Practical Cybersecurity, hosted by Jen Stone (MCIS, CISSP, CISA, QSA), is the bridge between complex security frameworks and real-world business implementation. Whether you are a "Jack of all trades" IT manager or a business leader with limited resources, this show provides the roadmap to a defensible security posture.
Practical Cybersecurity with Jen Stone
Your PCI Scope is Too Big (and how to fix it) Ep.12
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
How much of your business actually needs to be PCI compliant? Almost always less than you think.
Every system inside your PCI scope is something you have to secure, document, and prove — year after year. So the fastest way to cut the cost and effort of compliance isn't working harder on controls. It's making your scope smaller.
In this episode, Principal Security Analysts Jen Stone and Michael Simpson break down how PCI scope actually works — the three buckets every system falls into, the connected systems most people forget, and four practical ways to shrink your Cardholder Data Environment (and the bill that comes with proving it).
In this episode:
- What "in scope" really means, and why getting it wrong gets expensive
- The three scoping buckets: primary, secondary (connected), and out of scope
- The bucket almost everyone underestimates (hint: your Active Directory)
- Four ways to shrink your scope: segmentation, P2PE, tokenization, and fixing phone payments
- How taking payments by phone quietly balloons your scope, and the ways out
- Why "we use a third party" and "we're in the cloud" don't get you off the hook
- Three costly myths that keep merchants over-scoped and overspending
Free PCI scoping resources: https://listings.pcisecuritystandards.org/documents/Guidance-PCI-DSS-Scoping-and-Segmentation_v1.pdf
https://blog.pcisecuritystandards.org/new-information-supplement-pci-dss-scoping-and-segmentation-guidance-for-modern-network-architectures
Watch the full video version on YouTube: https://youtu.be/sSzZOGeGuYg
A note from Jen: We built Practical Cybersecurity because we were tired of the fear-mongering in this industry. Security shouldn't be a secret club.
Whether you're trying to figure out PCI compliance or need a pen test, my team at SecurityMetrics can help you out: https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place
But if you just want to learn how to protect yourself for free, start here: https://academy.securitymetrics.com/