Scope can be reduced with the use of segmentation, which isolates the cardholder data environment
from the remainder of an entity’s network. Reduction of scope can lower the cost of the PCI DSS
assessment, lower the cost and difficulty of implementing and maintaining PCI DSS controls, and
reduce risk for the entity. To be considered out of scope for PCI DSS, a system component must be
properly isolated (segmented) from the CDE, such that even if the out-of-scope system component
was compromised it could not impact the security of the CDE. For more information on scoping, see
the PCI DSS “Network Segmentation” section and Appendix D: Segmentation and Sampling of Business
Facilities/System Components