Structure for recording where the scope boundary runs and how the room is labeled to match. This template does not interpret any PCI DSS requirement, determine scope, assert that a requirement is satisfied, or replace the judgment of the assessor or the entity.
Assessment and vocabulary#
- Register ID / revision / prepared by / date:
- PCI DSS version named in the assessment:
- Source used for the requirement text:
- Date the scope states were defined:
- Definition source for the scope states:
- Scope decision owner:
Scope states in use#
- In scope — local wording:
- Connected to or security-impacting — local wording:
- Out of scope — local wording:
- Where the wording appears (diagram / register / cage / cabinet / port strip):
Boundary inventory#
For each boundary, record one row.
- Boundary ID:
- Type (cage / cabinet / panel / port range):
- Location reference:
- Scope state:
- Label text carried:
- Faces labeled (front / rear / both):
- Last verified on / by:
Cross-connects crossing the boundary#
- Local circuit ID:
- Provider circuit ID:
- Provider and order reference:
- A-end label / location:
- B-end label / location:
- In-scope cabinet touched:
- Present in scope register (yes / no):
- Last verified on / by:
Removable media and portable devices#
- Object ID:
- Identifier carried on the object:
- Where movement is recorded:
- Movement approver:
- Current location / status:
Two-way reconciliation#
- Population described as:
- Population extraction date:
- Exclusions and why:
- Direction one — register to room: run on / by / findings:
- Direction two — room to register: run on / by / findings:
Exception log#
- Exception ID:
- Found on / by / direction:
- What was found:
- Owner:
- Approved by / date:
- Closed on, or open with target date:
Statement of limits#
- What this register supports:
- What this register does not establish:
- Open items carried into the assessment:
Use it with these guides
Label the PCI DSS scope boundary so the room matches the diagram ↗