PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum  

Go Back   PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum > Payment Card Industry Data Security Standard Frequently Asked Questions (PCI DSS FAQ) > Protect Cardholder Data > [PCI-DSS] Requirement 3: Protect stored cardholder data

[PCI-DSS] Requirement 3: Protect stored cardholder data Encryption is a critical component of cardholder data protection. If an intruder circumvents other network security controls and gains access to encrypted data, without the proper cryptographic keys, the data is unreadable and unusable to that person. Other effective methods of protecting stored data should be considered as potential risk mitigation opportunities. For example, methods for minimizing risk include not storing cardholder data unless absolutely necessary, truncating cardholder data if full PAN is not needed, and not sending PAN in unencrypted e-mails.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-18-2007, 02:52 AM
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Jul 2002
Posts: 229
Default [PCI-DSS] 3.2.2 Do not store the card-verification code or value (three-digit or four-digit number printed on the front or back of a payment card) used to verify card-not-present transactions.

[PCI-DSS] 3.2.2 Do not store the card-verification code or value (three-digit or four-digit number printed on the front or back of a payment card) used to verify card-not-present transactions.

Note: See PCI DSS Glossary of Terms, Abbreviations, and Acronyms for additional information.


3.2.2 For a sample of system components, verify that the three-digit or four-digit card-verification code or value printed on the front of the card or the signature panel (CVV2, CVC2, CID, CAV2 data) is not stored under any circumstance:
  • Incoming transaction data
  • All logs (for example, transaction, history, debugging, error)
  • History files
  • Trace files
  • Several database schemas
  • Database contents
Reply With Quote
  #2  
Old 08-03-2009, 05:49 AM
Lemnik Lemnik is offline
Junior Member
 
Join Date: Aug 2009
Posts: 1
Default

In one of our markets we have extremely high levels of credit-card fraud. In order to combat this problem, we make phone calls directly to peoples banks in order to authorize the transfer. However the banks require that we give the CVV number over the phone. Is it possible for us to store the CVV number in our system somehow, or do we need to find another way to get it from the client (the card details are only stored until the payment is authorized or until a timeout, and only 2 people have access to the details)?
Reply With Quote
Reply

Bookmarks
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[PA-DSS] 1.1.2 After authorization, do not store the card-validation value or code (three-digit or four-digit number printed on the front or back of a payment card) used to verify card-not-present transactions admin [PA-DSS] 1. Do not retain full magnetic stripe, card validation code or value (CAV2, CID, CVC2, CVV 0 03-18-2007 02:41 AM


All times are GMT -4. The time now is 04:39 AM.


All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest ©1997 - 2010 by PCIDSSFAQ.ORG, except where noted otherwise.
Powered by vBulletin, Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
PCI-DSS Forum  |  PA-DSS Forum