This volume of the book deals with the single most important issue in PCI DSS, namely identifying which people, processes and technologies must be subjected to PCI DSS controls. This volume details how to approach scoping and provides references to various PCI DSS standard documents that support the approach.