Regulatory scope is a security architecture question

Which systems fall inside a regulation is determined by how you have built things, and it can be changed by building differently.

Segmenting the systems that handle regulated data reduces the scope of assessment, the cost of compliance and the blast radius simultaneously. Scope is usually treated as a fact to be discovered rather than a design decision, which leaves the largest available saving untouched.

More on Regulation and law