AI architectureAI Shared-Responsibility Mapping
AI shared-responsibility mapping assigns control duties across model providers, cloud platforms, application teams, data owners, users, and oversight functions.
Privacy engineering techniqueAnonymization and Pseudonymization
Anonymization aims to prevent data from being linked to an identifiable person, while pseudonymization replaces direct identifiers but retains a controlled path to re-link the data.
Service managementApproved Scanning Vendor Scans
Approved Scanning Vendor scans provide externally performed vulnerability scanning for applicable internet-facing systems under PCI scanning rules, with defined scope, evidence, dispute, remediation, and passing criteria.
Vulnerability referenceCVE, CWE, CVSS, and EPSS
CVE identifies publicly disclosed vulnerabilities, CWE describes classes of weakness, CVSS expresses technical severity, and EPSS estimates the probability of near-term exploitation.
Service managementCardholder Data Environment
The cardholder data environment includes the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, together with connected or security-impacting components in scope.
Service managementChange Enablement Practice
Change enablement maximizes successful changes by assessing risk, authorizing work, coordinating schedules, preserving evidence, and learning from results without imposing unnecessary friction.