Куда я попал?
PCI PIN Security v3.1
Framework
П.4-1
Для проведения оценки соответствия по документу войдите в систему.
Список требований
-
PIN Security Requirements:
4-1 Transactions may be stored and forwarded under certain conditions as noted in ISO 9564. PIN blocks, even encrypted, must not be retained in transaction journals or logs. PIN blocks are required in messages sent for authorization but must not be retained for any subsequent verification of the transaction. Transaction PINs shall only exist for the duration of a single transaction (the time between PIN entry and verification, i.e. store and forward). For the storage of other data elements, see the PCI Data Security Standards.
Testing Procedures:
4-1 Interview appropriate personnel to determine whether PINs are stored or retained for some period of time as part of a store-and-forward environment:- Examine transaction journals/logs to determine the presence of PIN blocks. If present, PIN blocks—whether enciphered or not—must be masked before the record is logged. For environments using online transaction monitors (e.g., CICS), specifically note how management is ensuring that PINs are not stored in online transaction journals.
- For entities that drive POS devices, examine documentation (operating procedures) to verify the disposition of PIN blocks when communication links are down.
Название | Severity | IP | Integral | |
---|---|---|---|---|
1111111 111 11 1111 11111111111111111 1111111 1 11111111111111111 |
-
|
1 |
-
|
|
11 111111111 111 1111111111111111111111111 1111 1 11111 1111111 |
-
|
1 |
-
|
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.