![]() |
|
|||||||
| [PCI-DSS] Requirement 3: Protect stored cardholder data Encryption is a critical component of cardholder data protection. If an intruder circumvents other network security controls and gains access to encrypted data, without the proper cryptographic keys, the data is unreadable and unusable to that person. Other effective methods of protecting stored data should be considered as potential risk mitigation opportunities. For example, methods for minimizing risk include not storing cardholder data unless absolutely necessary, truncating cardholder data if full PAN is not needed, and not sending PAN in unencrypted e-mails. |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||
|
||||
|
[PCI-DSS] 3.5 Protect cryptographic keys used for encryption of cardholder data against both disclosure and misuse:
3.5 Verify processes to protect keys used for encryption of cardholder data against disclosure and misuse by performing the following: |
|
#2
|
|||
|
|||
|
Hi,
Our organizaiton is accessing the client systems via Citrix program neighborhood application. No local storage of card holder data is possible. But our team can view the PAN information. As far as the requirement 3.3 is concerned, this is a legitimate business requirement and appropriate approvals for the same can be obtained. Now, in this situation, as the cardhodler information can only be viewed, and it being a legitimate business requirement, can the control 3.5 be considered as "Not Applicable"? If not, then I would appreciate if you could let me know the reason. Thanks in anticipation! |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| [PA-DSS] 2.5 Payment application must protect encryption keys used for encryption of cardholder data against disclosure and misuse | admin | [PA-DSS] 2. Protect stored cardholder data | 8 | 05-24-2010 07:28 AM |
| [PA-DSS] 2.4 If disk encryption is used (rather than file- or column-level database encryption), logical access must be managed independently of native operating system access control mechanisms (for example, by not using local user account databases). Decryption keys must not be tied to user accounts | admin | [PA-DSS] 2. Protect stored cardholder data | 0 | 03-18-2007 02:43 AM |