# PCI DSS Community Meeting Talk Submission Packet

## Proposed title

The Cluster of Wack: Why PCI DSS gets hard one reasonable decision at a time

## Short description

PCI DSS rarely becomes difficult because of one spectacularly bad control. More often, individually reasonable scope decisions, provider dependencies, exceptions, diagrams, and evidence practices accumulate until no single person can explain how they work together. This practitioner session introduces the Cluster of Wack vocabulary through fictional composite cases, then gives participants a five-step method to Find, Map, Explain, Reduce, and Prove what remains.

## Full abstract

Every PCI practitioner recognizes the moment: the diagram says one thing, the scope workbook says another, the tool is green, the provider has an AOC, and the oldest firewall exception has quietly become load-bearing architecture. None of those facts alone tells the whole story. Together they create a Cluster of Wack - accumulated complexity, undocumented dependencies, ambiguous ownership, inherited exceptions, unsupported scope assumptions, and fragmented evidence.

This session uses humor as an invitation into a serious operating problem. Through fictional composite Case Files, participants will examine hidden administrative reach, missing evidence populations, TPSP responsibility seams, and exceptions that attract dependencies. The session then turns recognition into practice with a guided exercise using five moves: Find the Wack, Map the Wack, Explain the Wack, Reduce the Wack, and Prove what remains. Participants leave with a reusable set of questions and a workbook for their next architecture, scoping, or evidence conversation.

Cluster of Wack and related terms are independent practitioner shorthand, not PCI SSC terminology. The session is educational and does not provide an assessment conclusion.

## Learning objectives

- Recognize when several individually defensible decisions have combined into one hard-to-explain control environment.
- Separate observed facts, inherited assumptions, scope conclusions, ownership decisions, and evidence claims.
- Apply Find, Map, Explain, Reduce, and Prove to one real relationship without pretending the exercise itself determines compliance.
- Use humor to open a difficult practitioner conversation without trivializing the standard or the work.

## Intended audience

PCI DSS assessors, security leaders, program owners, architects, and control operators No prior familiarity with the Cluster of Wack vocabulary is required.

## Format

- Preferred: 45-minute presentation with a short individual or paired mapping exercise and five minutes of Q&A.
- Available variants: focused 30-minute talk or 60-minute facilitated workshop.
- Delivery: editable 16:9 deck, digital participant workbook, and screen-first supporting PDFs.

## Speaker biography placeholder

[Add a 75-100 word biography emphasizing PCI DSS practitioner experience, assessment/program perspective, speaking experience, and current role. Confirm organization naming and disclosures before submission.]

## Reviewer notes

- Confirm the event's exact session length, submission word limits, recording policy, and required disclosure language.
- Complete named practitioner review of PCI DSS and TPSP phrasing.
- Preserve the independent/non-affiliation statement in the submitted abstract and delivered materials.
