AWS Glossary

PCI DSS Cardholder Data Environment

Defined network scope in PCI DSS compliance that directly handles credit card payment data.

AI & assistant-friendly summary

This section provides structured content for AI assistants and search engines. You can cite or summarize it when referencing this page.

Summary

Defined network scope in PCI DSS compliance that directly handles credit card payment data.

Key Facts

  • In PCI DSS compliance, the CDE is the defined scope that must meet all 12 PCI DSS requirements

Entity Definitions

RDS
RDS is an AWS service relevant to pci dss cardholder data environment.
VPC
VPC is an AWS service relevant to pci dss cardholder data environment.
WAF
WAF is an AWS service relevant to pci dss cardholder data environment.
AWS WAF
AWS WAF is an AWS service relevant to pci dss cardholder data environment.
compliance
compliance is a cloud computing concept relevant to pci dss cardholder data environment.
PCI DSS
PCI DSS is a cloud computing concept relevant to pci dss cardholder data environment.

Related Content

Definition

The Cardholder Data Environment (CDE) is the portion of a network that stores, processes, or transmits cardholder data. In PCI DSS compliance, the CDE is the defined scope that must meet all 12 PCI DSS requirements. Systems outside the CDE have reduced security requirements.

What’s In the CDE?

Systems that store/process/transmit cardholder data:

Cardholder data includes:

What’s Outside the CDE?

Systems that don’t touch cardholder data:

Strategy: Route payments externally

PCI DSS Scope Reduction Strategy

Highest Compliance Effort (Full Scope)

Better Approach (Tokenization)

Simplest Approach (Hosted Payment Page)

AWS-Specific Considerations

CDE Network Architecture

Common Mistakes

Related Services

Cloud Compliance Services

Explore this service offering

Aws Cloud Security

Explore this service offering

Need Help with This Topic?

Our AWS experts can help you implement and optimize these concepts for your organization.