Monday, December 5, 2016

PCI DSS - account data, cardholder data, SAD(Sensitive Authentication Data)

We normally think that account data and cardholder data are the same. But it is not so.
    - Cardholder data is a subset of account data

    - Account Data = Cardholder data + SAD
           - Account data includes all of the information printed on the physical card as well as data on the magnetic stripe or chip

   - Cardholder data
      - Primary Account Number(PAN)
      - Cardholder Name
      - Expiration Data
      - Service code

  - SAD
       - Full Track Data(magnetic stripe data or equivalent on a chip)
       - CAV2, CVC2, CVV2, CID
       - PINs/PIN blocks

No comments:

Post a Comment