02.02.2013 Views

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Security<br />

8.4 PIN and Key Management Security Requirements<br />

• Assessment of the physical security of the vendor’s site, and<br />

• Assessment of the logical security of the vendor’s data network environment,<br />

hardware, and software. All personalizers using an Internet connection or<br />

wireless LAN to transfer Issuer or Cardholder data must also undergo a<br />

network security scan as described in Rule 8.6 of the Site Data Protection<br />

Program.<br />

The list of vendors that the Corporation has certified to provide Card production<br />

services, Certified Vendors (for Card Production Services of Any <strong>MasterCard</strong>,<br />

<strong>Maestro</strong>, or Cirrus Branded Card) is continually updated. From time to time,<br />

the Corporation distributes the current list, which supersedes all previously<br />

published lists, in a <strong>Global</strong> Security Bulletin.<br />

8.3.1.2 Card Design and Production<br />

Prior to production, one full color reproduction of the Card with the appropriate<br />

Marks must be submitted to the Licensing & Approvals department for approval.<br />

When approval is granted, the manufacturer must send two (2) sample Cards of<br />

the actual printed stock to the Licensing & Approvals department.<br />

Only after written confirmation of the Card design approval, may the<br />

manufacturer manufacture and deliver the Cards to the Issuer. Subsequent<br />

deliveries of an unchanged Card design do not require separate approval.<br />

8.4 PIN and Key Management Security Requirements<br />

All Customers acquiring PIN transactions must comply with the security<br />

requirements for PIN and key management as specified in the Payment Card<br />

Industry PIN Security Requirements.<br />

All Customers performing Issuer PIN processing must refer to the Issuer PIN<br />

Policy and Guidelines for all aspects of Issuer PIN management and PIN key<br />

management including PIN selection, transmission, storage, usage guidance,<br />

and PIN change.<br />

8.4.1 PIN Verification<br />

The Issuer is permitted to use the PIN verification algorithm of its preference.<br />

Refer to “PIN Generation Verification” in the Single Message System<br />

Specifications, Chapter 6, “Encryption,” for more information about PIN<br />

verification that the Single Message System performs directly for <strong>Maestro</strong> Issuers.<br />

Refer to “PIN Verification” in the Authorization System Manual, Chapter 9,<br />

“Authorization Services Details,” for more information about the <strong>MasterCard</strong> PIN<br />

verification service, in which Single Message System performs PIN verification<br />

on behalf of <strong>MasterCard</strong> issuers, and the two PIN verification methods (IBM<br />

3624 and ABA) supported by the PIN verification service.<br />

©1993–2012 <strong>MasterCard</strong>. Proprietary. All rights reserved.<br />

<strong>Maestro</strong> <strong>Global</strong> <strong>Rules</strong> • 9 November 2012 8-3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!