31.07.2015 Views

Download

Download

Download

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Protect Cardholder Data • Chapter 9 285Figure 9.2 File Based Encryption vs. Full Disk EncryptionDatabase (Column-level) EncryptionUltimately, the most crucial element of cardholder data that needs to be rendered “unreadable”wherever it is stored, is what PCI DSS refers to as the Personal Account Number(PAN).This is the full account number that identifies both the issuer of the card and thecardholder account. PCI DSS 3.4 states “The MINIMUM account information that must berendered unreadable is the PAN.”This is not to say that other elements of cardholder data would not benefit from beingencrypted. But since this data is necessary to be stored, it needs to be protected. Other itemsof data pulled from a card during normal business are never to be stored, and thus shouldnot be residing in a stored database.Column-level encryption allows a more granular approach to rendering the key cardholderdata unreadable, by focusing on the specific data that needs to be protected.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!