CyberTRIZPEDIA

Protect Stored Cardholder Data with Strong Cryptography

Control
PCI-ENCRYPT-001
Regulation
PCI DSS
Category
operational
Priority
critical
Frequency
annually
Type
operational

What this control requires

Implement strong cryptography (AES-256 or equivalent) for stored cardholder data. Never store sensitive authentication data after authorisation. Implement key management procedures covering key generation, distribution, storage, replacement, destruction and split knowledge/dual control for cryptographic key custodians. Document the data retention and disposal policy.

Other PCI DSS controls