PCI DSS 4.0 12.5.2: 12.5.2 Annual and change-driven scope confirmation
The entity must document its PCI DSS scope and confirm it at least once every 12 months, plus whenever the in-scope environment changes significantly. The scoping validation must at minimum: identify all data flows across payment stages (for instance authorisation, capture, settlement, chargebacks, refunds) and every acceptance channel (for instance card-present, card-not-present, e-commerce); update all data-flow diagrams under Requirement 1.2.4; identify every place where account data is held, processed or sent, including places outside the current CDE, applications handling CHD, data transmitted across networks and systems, and backups of files; identify all components in, connected to, or able to affect the CDE; identify all segmentation controls and the environments segmented from the CDE, with justification for out-of-scope environments; identify all third-party connections with CDE access; and confirm all these items are included in scope. Applicability: this is the entity's own confirmation and is separate from, and not replaced by, the assessor's scoping check during the annual assessment. Objective under the customized approach: scope is checked periodically and after significant change through thorough analysis and suitable technical measures.
This control maps to 70 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 12.5.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.