Protecting Cardholder Data
In order to protect cardholder data, it’s important to first understand what it is and where it can be found. The PCI DSS applies wherever account data (such as a primary account number from a credit card) is stored, processed or transmitted.
Account data consists of Cardholder Data plus Sensitive Authentication Data:
|
|
- Primary Account Number (PAN)
- Cardholder Name
- Expiration Date
- Service Code
|
- Full magnetic stripe data or equivalent data on a chip
- CAV2/CVC2/CVV2/CID
- PINs/PIN blocks
|
Location of Cardholder Data and Sensitive Authentication Data
Sensitive authentication data consists of magnetic stripe (or track) data, card validation code or value, and PIN data. Storage of this data is strictly prohibited, as detailed in the PCI DSS 2.0. This data is extremely valuable to hackers because it allows them to generate fake payment cards and create fraudulent transactions.
For more information, visit the PCI Security Standards council at www.pcisecuritystandards.org.