PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum  

Go Back   PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum > PA-DSS - Payment Application Data Security Standards > [PA-DSS] 2. Protect stored cardholder data

[PA-DSS] 2. Protect stored cardholder data Protect stored cardholder data

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-18-2007, 02:44 AM
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Jul 2002
Posts: 229
Default [PA-DSS] 2.7 Securely delete any cryptographic key material or cryptogram stored by previous versions of the payment application, in accordance with industry-accepted standards for secure deletion, as defined, for example the list of approved products maintained by the National Security Agency, or by other State or National standards or regulations. These are cryptographic keys used to encrypt or verify cardholder data

2.7 Securely delete any cryptographic key material or cryptogram stored by previous versions of the payment application, in accordance with industry-accepted standards for secure deletion, as defined, for example the list of approved products maintained by the National Security Agency, or by other State or National standards or regulations. These are cryptographic keys used to encrypt or verify cardholder data.

PCI Data Security Standard Requirement 3.6

Note: this requirement only applies if previous versions of the payment application used cryptographic key materials or cryptograms to encrypt cardholder data.

Testing Procedures:

2.7.a Review the PA-DSS Implementation Guide prepared by the vendor and verify the documentation includes the following instructions for customers and resellers/integrators:
  • That cryptographic material must be removed
  • How to remove cryptographic material
  • That such removal is absolutely necessary for PCI DSS compliance
  • How to re-encrypt historic data with new keys.

2.7.b Verify vendor provides a secure wipe tool or procedure to remove cryptographic material.

2.7.c Verify, through use of forensic tools and/or methods, that the secure wipe tool or procedure securely removes the cryptographic material, in accordance with industry-accepted standards for secure deletion of data.
Reply With Quote
Reply

Bookmarks
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[PA-DSS] 2.6 Payment application must implement key management processes and procedures for keys used for encryption of cardholder data admin [PA-DSS] 2. Protect stored cardholder data 0 03-18-2007 02:44 AM
[PA-DSS] 1.1.4 Securely delete any magnetic stripe data, card validation values or codes, and PINs or PIN block data stored by previous versions of the payment application, in accordance with industry-accepted standards for secure deletion, as defined, for example by the list of approved products maintained by the National Security Agency, or by other State or National standards or regulations admin [PA-DSS] 1. Do not retain full magnetic stripe, card validation code or value (CAV2, CID, CVC2, CVV 0 03-18-2007 02:41 AM


All times are GMT -4. The time now is 04:38 AM.


All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest ©1997 - 2010 by PCIDSSFAQ.ORG, except where noted otherwise.
Powered by vBulletin, Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
PCI-DSS Forum  |  PA-DSS Forum