Schrödinger’s Scope

Scope is not defensible when a system is excluded from control testing but included whenever the organization needs it to explain how the CDE is operated or secured.

A shared identity platform is absent from the scope inventory because it stores no account data. The access-control narrative relies on it. Administrator authentication relies on it. Evidence comes from it. During control testing it becomes “enterprise infrastructure.” During architecture review it becomes essential.

A scope conclusion should reflect how the environment actually stores, processes, transmits, connects to, administers, and affects the security of account data systems. The exact conclusion depends on facts; the contradiction is the diagnostic signal.

When scope changes with the question, evidence loses context. The organization cannot show which population was tested, why supporting systems were trusted, or how the stated boundary was maintained.

  1. Does the component administer, authenticate, configure, monitor, or secure in-scope systems?
  2. Can it connect to the CDE directly or through another system?
  3. Would its compromise affect the security of account data or a relied-upon control?
  4. Is the same classification used in diagrams, inventories, narratives, and evidence requests?