Home > Security Video Library > PCI compliance requirement 3: Protect data

PCI compliance requirement 3: Protect data:

EMAIL THIS

PCI compliance requirement 3: Protect data

DATE: 01 Jun 2009


Diana Kelley and Ed Moyle, co-founders of Security Curve, review PCI compliance Requirement 3: "Protect stored cardholder data." PCI compliance Requirement 3 calls for:

  • Encryption of stored data
  • Protection of sensitive authentication data, like mag stripes. This cardholder data must not be stored, even with encryption.

Ed Moyle and Diana Kelley review common questions related to PCI compliance requirement 3, including "What's Appendix B all about?" and "Should the CVV never be stored?"

Watch the rest of the PCI compliance requirement videos.

Editor's note: This video is based on PCI DSS version 1.1. For updated information on the changes in PCI DSS version 1.2, see the following:

 More on PCI Data Security Standard


PCI compliance requirement 12: Policy
VIDEO - To pass the Payment Card Industry Data Security Standard, particularly Requirement 12, it's important that you maintain a body of policy or documentation of how you will address ...
( Jun 01, 2009 )


PCI compliance requirement 11: Testing
VIDEO - PCI Requirement 11 is a popular one, according to Diana Kelley. Learn why in this instructional video.
( Jun 01, 2009 )


PCI compliance requirement 10: Auditing
VIDEO - Diana Kelley and Ed Moyle of Security Curve review PCI compliance requirement 10: "Track and monitor all access to network resources and cardholder data."
( Jun 01, 2009 )

PCI DSS compliance help: Using frameworks, technology ...
LEARNING GUIDE - This mini-guide offers a variety of tips on how organizations can use several frameworks, technologies and standards to help manage PCI DSS efforts and ease the compliance burden.
( Nov 23, 2009 )

Five things to do before your first PCI DSS compliance ...
TIP - Put these steps in motion before your organization's first PCI DSS compliance audit
( Nov 19, 2009 | SearchMidmarketSecurity.com )

Chip and PIN adoption
- Chip and PIN use in Europe and the UK has resulted in reducing fraud, according to some studies. Why doesn't the payment industry push chip and PIN adoption in the United States?
( Nov 02, 2009 )

Chip and PIN adoption serves lesson for U.S. payment ...
OPINION - As payment processors offer plans for end-to-end encryption, the UK is finding success with chip and pin deployments. The U.S. payment industry should take notice, expert says.
( Oct 29, 2009 )

Heartland CIO on end-to-end encryption, credit card ...
INTERVIEW - In this interview, Heartland CIO Steven Elefant explains Heartland's E3 end-to-end encryption plan and explains how some tokenization plans could create security weaknesses.
( Oct 26, 2009 )
ADVERTISEMENT

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts