PCI Compliance
PCI Compliance Made Simple
What are the problems in PCI Compliance for the payments industry?
• Fraud Losses
• Card reissuance costs
• Cardholder inconvenience
• Loss of consumer confidence
• Adverse publicity – Brand & Reputation damage
• Legislative interest – Threat of governmental regulation
What is a Compromise?
A compromise is when an attacker takes advantage of a flaw in a system that processes, stores and/or transmits data. The attacker is trying to gain access to card numbers, expiration dates, CVV2/CVC2/CID, and/or magnetic strip data.
What is allowed to be stored, transmitted, or processed?
Encrypted Primary Account Number (PAN), expiration date, and the name is permitted.
How should the PAN be protected when stored?
It should be encrypted, hashed or truncated.
What must not be stored post-authorization?
CVV2/CVC2, full track data(Track 1and Track 2), and PIN block cannot be stored.