The entity considers any cardholder data found to be in scope of the PCI DSS assessment and part
of the CDE. If the entity identifies data that is not currently included in the CDE, such data should
be securely deleted, migrated/consolidated into the currently defined CDE, or the CDE redefined to
include these data