Which of the following best describes the scope of a PCI DSS compliance assessment?
-
A
All systems in the corporate network
-
B
Only systems that store cardholder data
-
C
All system components that store, process, or transmit cardholder data, plus connected systems
-
D
Only point-of-sale terminals