Requirement 3 Flashcards
What is requirement 3?
Protect stored account data
Storage of account data is kept to
A minimum —– the more you store the more you have to protect
What kind of data is not stored after authorization?
Sensitive Authentication Data (SAD)
(including card validation codes/values, (CVCs/CVVs), full track data — from the magnetic stripe or equivalent on a chip PINs, etc)
What is PAN?
Primary Account Number
What should be done to PAN when it is stored?
It (PAN) needs to be secured
What cannot be displayed in full nor copied?
PAN and cardholder data
What are used to protect stored account data?
Cryptographic keys – these need to be secured
In regard to cryptographic keys for stored account data, what needs to be defined and implemented?
Key management processes and procedures for the entire key lifecycle