PDA

View Full Version : PAN (account number / card number) digits to be displayed


Axel Gromann
02-14-2007, 02:09 PM
Query regarding discrepancy between “PCI DSS – Security Audit Procedures” item 3.3 and “PCI Self Assessment Questionnaire” item 3.4

Hi!
Please note that we have come across a discrepancy between the above. The audit procedures stipulate that masking of PAN should be in line with the following: “the first six and last four digits are the maximum number of digits to be displayed”, while the Questionnaire asks whether “all but the last four digits of the account number (are) masked”.
The latter being the no doubt more secure, the self assessing party would fail if it were to adhere to the audit procedure requirements and displayed the first six and last four.

Please advise whether this is/has been addressed and confirm the prudent course of action.

Right now I would take the stance that the QSA should use his better judgement and let the questionnaire item pass as adequate if the fist six and last four are displayed, since this is the standard’s requirement and was stipulated as such in the course.


Quotes out of “PCI DSS – Security Audit Procedures” item 3.3 and “PCI Self Assessment Questionnaire” item 3.4 as follows:
PCI DSS – Security Audit Procedures
3.3
Mask PAN when displayed (the first six and last four digits are the maximum number of digits to be displayed).

PCI Self Assessment Questionnaire
3.4
Are all but the last four digits of the account number masked when displaying cardholder data

Thanks,
Ax.

admin
02-15-2007, 10:28 AM
It is acceptable, when masking, to show the first 6 and last 4 digits (thus masking the middle digits.)

It is important to point out the difference in terminology:

'masking' = showing only partial information when displaying on-screen or printing out.

'truncating' = removing part of the number when stored on disk

'hashing' = performing a one-way cryptographic function that cannot be reversed.

Axel Gromann
02-15-2007, 07:36 PM
Agree and am aware of the above (as indicated in initial query).
This does however not address the inconsistency between both documents and it does not not necessarily give a card blanche for disregarding the questionnare's required value of "only the last 4 digits:".
Not only does the questionnaire / audit procedure difference make the QSA look unprofessional or inconsistent, it also give rise to customer questions.
I guess your answer confirms my initial statement but I was hoping for a reason for the difference and possibly a "The audit procedures and questionnaire will have to be aligned". :)
Thanks, Ax.

admin
02-15-2007, 10:19 PM
The audit procedures and questionnaire will have to be aligned. :)