CyberTRIZPEDIA

Cardholder Data Inventory and Protection

Control
PCI-R3-001
Regulation
PCI DSS
Category
technical
Priority
critical
Frequency
quarterly
Type
technical

What this control requires

Maintain a current inventory of all cardholder data (CHD) storage locations. Implement strong cryptography (AES-256 minimum) for all stored PAN. Never store sensitive authentication data (SAD) after authorisation. Document data flows and implement data discovery to find undiscovered CHD storage.

Other PCI DSS controls