PCI 3:: Difference between revisions
Jump to navigation
Jump to search
No edit summary |
No edit summary |
||
Line 1: | Line 1: | ||
== Requirement 3: Protect stored data. == | |||
<br> | <br> | ||
* Note that this does not apply to those employees and other parties with a specific need to see full credit card numbers. | * Note that this does not apply to those employees and other parties with a specific need to see full credit card numbers. |
Revision as of 16:34, 7 July 2006
Requirement 3: Protect stored data.
- Note that this does not apply to those employees and other parties with a specific need to see full credit card numbers.
- One-way hashes (hashed indexes), such as SHA-1
- Truncation
- Index tokens and PADs, with the PADs being securely stored
- Strong cryptography, such as Triple-DES 128-bit or AES 256-bit with associated key management processes and procedures.
- The MINIMUM account information that needs to be rendered unreadable is the payment card account number.
- PCI-3.5 Protect encryption keys against both disclosure and misuse.
- PCI-3.6 Fully document and implement all key management processes and procedures, including:
--Mdpeters 08:33, 26 June 2006 (EDT)