Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

FAQ 1084 Updated

What is the intent of PCI DSS Requirement 3.4.1?

The intent of this requirement is to address the acceptability of disk encryption for rendering cardholder data unreadable. Disk encryption encrypts data stored on a computer’s mass storage and automatically …

FAQ 1139 Updated

Does PCI DSS allow faxing of payment card numbers?

Any cardholder data that is stored, processed, or transmitted must be protected in accordance with PCI DSS. If faxes are sent or received via modem over a traditional PSTN phone …

FAQ 1304 Updated

To which devices does PCI DSS Requirement 10.4.2 apply?

PCI DSS Requirement 10.4.1 defines several events and system types that require daily log reviews, but Requirement 10.4.2 allows the organization to determine the log review frequency for all other …

FAQ 1146 Updated

What is the difference between masking and truncation?

Masking is addressed in PCI DSS Requirement 3.4.1, whereas truncation is one of several options specified to meet PCI DSS Requirement 3.5.1.

Requirement 3.4.1 relates to the protection of …