Connected-to or Security-Impacting System
PCIComplianceHubLast updated
A system component that does not store, process or transmit account data itself but can still affect the security of the cardholder data environment, and is therefore in scope for PCI DSS. Typical examples are directory services, name resolution, patch and configuration management servers, monitoring and logging platforms, and administrative jump servers. PCI DSS scoping recognises three categories: CDE systems, connected-to or security-impacting systems, and out-of-scope systems. Underestimating this middle category is one of the most common scoping errors.
Applies to. Any system component outside the CDE that connects to it or can affect its security: directory and name services, patch and configuration management, logging and monitoring, backup, virtualisation hosts and jump servers.
Example. A central logging platform receives audit logs from CDE systems. It holds no account data, but it can alter or delete the evidence Requirement 10 depends on and it accepts connections from the CDE, so it is in scope and must meet the applicable requirements.
Limits. In scope is not the same as in the CDE: which requirements apply depends on what the system does and how it connects, and the entity documents that in its scope confirmation (12.5.2). Placing such a system on a separate network does not remove it from scope; only removing the connection and the ability to affect security does. Section 4 of the standard, on scope, describes the three categories.
Related. Cardholder Data Environment (CDE), Network Segmentation, Scoping, System Component, Jump Server, Audit Log / Audit Trail
Sources. PCI DSS v4.0.1 (June 2024)