Auditen
Home / Glossary / Scoping

Scoping

Also known as: Boundary definition, Audit scope determination, Inventory mapping

Scoping is the process of defining the specific boundaries of a compliance assessment or audit. It identifies which systems, processes, physical locations, and personnel are subject to evaluation based on applicable regulatory requirements or standards. This ensures that resources are focused only on relevant assets while explicitly excluding non-applicable areas.

In practice

During a PCI DSS audit, a practitioner performs scoping by mapping the flow of credit card data to identify every server, network segment, and application that touches that data, thereby isolating the "Cardholder Data Environment" from the rest of the corporate network.

More terms