Answer

How to reduce PCI scope with credit card tokenization

We are considering the implementation of a credit card tokenization system to support Payment Card Industry Data Security Standard (PCI DSS) compliance. For our environment, tokenization would ease compatibility with interconnected systems, whereas encryption would be much more challenging. However, does tokenization guarantee that we'll be able to scope out systems that would otherwise have to receive card data?

    Requires Free Membership to View



Tokenization is a fantastic way to reduce PCI scope for an organization. Systems that use tokenization essentially replace sensitive information (in this case, a credit card number) with nonsensitive information (a dummy data value known as a "token"). However, depending upon the specific tokenization mechanism used, it may be possible to reverse the process and retrieve the credit card number from the token.

Ask the Expert!

Got a vexing problem for Mike Chapple or any of our other experts? Ask your enterprise-specific questions today! (All questions are anonymous.)

The major benefit tokenization provides is that tokens (unless they can be reversed) are not sensitive information, and systems that need some way to reference a credit card number can store tokens without falling into scope of PCI DSS compliance. The situation you outline in your question (feeding data to external systems) sounds like an appropriate use of tokenization.

The PCI Security Standards Council, in its Tokenization Guidelines, outlines eight specific characteristics that tokenization solutions must meet:

  1. Tokenization systems must not reverse tokens to credit card numbers for any component outside of the organization's cardholder data environment.
  2. Systems performing the tokenization must be on secure internal networks that are isolated from out-of-scope networks.
  3. Untrusted communication must be prohibited in and out of the tokenization system.
  4. The solution must be built upon strong cryptography.
  5. The solution must meet the access control and authentication requirements in PCI DSS Sections 7 and 8.
  6. The solution must be securely configured with vulnerabilities remediated.
  7. The solution must implement the organization's data retention policy by secure deleting cardholder data when it is no longer necessary for meeting business requirements.
  8. The solution must provide appropriate monitoring, alerting and logging capabilities.

If your tokenization system meets these criteria, it is likely a great way to reduce the scope of your cardholder data environment and ease your PCI DSS compliance process.

This was first published in December 2012

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: