PDA

View Full Version : PCI DSS Applicability Information


Fieldofdreams
04-09-2007, 05:22 PM
In the new PCI DSS 1.1 there is a section headed "PCI DSS Applicability Information" that has a table of various definations... the question is should we encrypt CC Name and exp date??

K Heath
04-09-2007, 09:04 PM
There is no need to encrypt the Cardholder Name and Expiry Date. The last column of the table you refre to specifies the encryption requirement. The requirement for encryption of stored information (PCI DSS Req 3.4) applies only to the PAN (Primary Account Number).

mdahn
04-10-2007, 12:12 AM
This is correct. You can ignore the table if it confuses you. Just remember that:
1) You cannot save sensitive authentication information after authorization, and
2) You need to protect cardholder data, by encrypting it, or truncating it.