Is PAN, at a minimum, rendered unreadable anywhere it is stored (including data on portable digital media, backup media, and in logs,) by using any of the following approaches?The MINIMUM account information that must be rendered unreadable is the PAN.
- One-way hashes based on strong cryptography
- Truncation
- Index tokens and pads (pads must be securely stored)
- Strong cryptography with associated key management processes and procedures.
If for some reason, a company is unable to render the PAN unreadable, refer to Appendix B: "Compensating Controls."
Note: "Strong Cryptography" is defined in the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms.
You are not logged in, either login or create an account to post comments
posted by Precision at 9:03 AM on December 30, 2008