CyberTRIZPEDIA

Cardholder Data Transmission Encryption

Control
PCI-R4-001
Regulation
PCI DSS
Category
technical
Priority
critical
Frequency
quarterly
Type
technical

What this control requires

Protect cardholder data during transmission over public or untrusted networks using strong cryptography (TLS 1.2+ minimum, TLS 1.3 preferred). Inventory all CHD transmission paths. Disable SSLv3, TLS 1.0, and TLS 1.1. Never send PAN via email, messaging, or chat.

Other PCI DSS controls