PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum  

Go Back   PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum > PA-DSS - Payment Application Data Security Standards > [PA-DSS] 3. Provide secure authentication features

[PA-DSS] 3. Provide secure authentication features Provide secure authentication features

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-18-2007, 02:45 AM
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Jul 2002
Posts: 229
Default [PA-DSS] 3.3 Encrypt payment application passwords during transmission and storage, using strong cryptography based on approved standards (defined in PCI DSS Glossary, Abbreviations, and Acronyms)

3.3 Encrypt payment application passwords during transmission and storage, using strong cryptography based on approved standards (defined in PCI DSS Glossary, Abbreviations, and Acronyms).

PCI Data Security Standard Requirement 8.4

Testing Procedures:

3.3 Examine payment application password files during storage and transmission to verify that passwords are encrypted at all times.
Reply With Quote
  #2  
Old 08-30-2010, 12:55 PM
jgross jgross is offline
Junior Member
 
Join Date: Mar 2010
Posts: 2
Default

One of the biggest factors for card data theft is a result of ineffective protection against stored data, and not complying to PCI DSS. The industry is starting to trend toward tokenization technology more, to help limit this issue. The result is that the card information is transferred to a PCI DSS compliant data storage facility, leaving a unique identifier (token) that points to the actual data without containing any sensitive information itself.

This encryption technique is one that is becoming implemented more often in the industry, and the result is better security against data theft. There is good information about this technology in this tokenization white paper.
Reply With Quote
Reply

Bookmarks
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -4. The time now is 06:52 AM.


All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest ©1997 - 2010 by PCIDSSFAQ.ORG, except where noted otherwise.
Powered by vBulletin, Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
PCI-DSS Forum  |  PA-DSS Forum