PCI compliance requirement 3: Protect data

PCI compliance requirement 3: Protect data

PCI compliance requirement 3: Protect data

Date: Jun 01, 2009
Diana Kelley and Ed Moyle, co-founders of Security Curve, review PCI compliance Requirement 3: "Protect stored cardholder data." PCI compliance Requirement 3 calls for:

  • Encryption of stored data
  • Protection of sensitive authentication data, like mag stripes. This cardholder data must not be stored, even with encryption.

Ed Moyle and Diana Kelley review common questions related to PCI compliance requirement 3, including "What's Appendix B all about?" and "Should the CVV never be stored?"

Watch the rest of the PCI compliance requirement videos.

Editor's note: This video is based on PCI DSS version 1.1. For updated information on the changes in PCI DSS version 1.2, see the following:

More on PCI Data Security Standard