Contents
What should not be done with cardholder data?
Do not store cardholder data unless there is a legitimate business need; truncate or mask cardholder data if full PAN is not needed and do not send PAN in unencrypted emails, instant messages, chats, etc..
How long should you keep cardholder data?
➢ Pre-authorization Data including track, CVV2, and PIN information, will be retained only until completion of the authorization of a transaction. ➢ System and audit logs showing access to stored data must be retained for at least 1-year. Logs must be kept online and available for 90 days.
What does PCI DSS mean for cardholder data environment?
The PCI DSS security requirements apply to all system components included in or connected to the cardholder data environment. The cardholder data environment (CDE) is comprised of people, processes and technologies that store, process, or transmit cardholder data or sensitive authentication data.
What are the components of a cardholder data environment?
The cardholder data environment (CDE) is comprised of people, processes and technologies that store, process, or transmit cardholder data or sensitive authentication data. “System components” include network devices, servers, computing devices, and applications (page 10 of the PCI DSS).
How to reduce stress on cardholder data environment?
You can reduce the stress on your organisation by limiting your cardholder data environment (CDE), i.e. the places where sensitive information is stored. The PCI DSS requires organisations to take specific measures to protect their CDE, so it’s beneficial to make it as small as possible.
What are the challenges of scanning cardholder data?
Many organizations have a lot of challenges scanning systems with cardholder data especially when such systems up virtual or located at other environments, or not under full control of the merchant. Branden R. Williams,