Cyber Insurance Subjectivity Tracker

Controls / Sector rules (add-ons)

Stored card numbers are rendered unreadable wherever they are kept

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: make stored card numbers unreadable wherever they are kept.

In Australia

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 3.5.1
PCI DSS v4.0.1 (add-on)
Stored PAN rendered unreadable

PAN must be made unreadable wherever it is stored, using one of these methods: (1) one-way hashes of the whole PAN based on strong cryptography; (2) truncation, where hashing may not substitute for the removed segment, and where hashed and truncated forms, or differing truncation formats, of the same PAN coexist in an environment, added controls must stop them being correlated to rebuild the original; (3) index tokens; (4) strong cryptography with supporting key-management processes and procedures. Applicability: covers PAN in primary storage (databases, flat files such as text files or spreadsheets) and non-primary storage (backups, audit, exception or troubleshooting logs); temporary files holding cleartext PAN during encryption and decryption are not prohibited. Customized approach objective: PAN held on any storage media is never readable in the clear.

evidence an assessor asks for Data storage inventory mapping each PAN location to its protection method; Encryption, hashing, truncation or tokenization design documentation including algorithms; Sample database and log extracts showing PAN unreadable; Backup and archive encryption evidence; Controls preventing correlation of hashed and truncated values (for example keyed hashing, segregation)

In the United States

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 3.5.1
PCI DSS v4.0.1 (add-on)
Stored PAN rendered unreadable

PAN must be made unreadable wherever it is stored, using one of these methods: (1) one-way hashes of the whole PAN based on strong cryptography; (2) truncation, where hashing may not substitute for the removed segment, and where hashed and truncated forms, or differing truncation formats, of the same PAN coexist in an environment, added controls must stop them being correlated to rebuild the original; (3) index tokens; (4) strong cryptography with supporting key-management processes and procedures. Applicability: covers PAN in primary storage (databases, flat files such as text files or spreadsheets) and non-primary storage (backups, audit, exception or troubleshooting logs); temporary files holding cleartext PAN during encryption and decryption are not prohibited. Customized approach objective: PAN held on any storage media is never readable in the clear.

evidence an assessor asks for Data storage inventory mapping each PAN location to its protection method; Encryption, hashing, truncation or tokenization design documentation including algorithms; Sample database and log extracts showing PAN unreadable; Backup and archive encryption evidence; Controls preventing correlation of hashed and truncated values (for example keyed hashing, segregation)

In United Kingdom

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 3.5.1
PCI DSS v4.0.1 (add-on)
Stored PAN rendered unreadable

PAN must be made unreadable wherever it is stored, using one of these methods: (1) one-way hashes of the whole PAN based on strong cryptography; (2) truncation, where hashing may not substitute for the removed segment, and where hashed and truncated forms, or differing truncation formats, of the same PAN coexist in an environment, added controls must stop them being correlated to rebuild the original; (3) index tokens; (4) strong cryptography with supporting key-management processes and procedures. Applicability: covers PAN in primary storage (databases, flat files such as text files or spreadsheets) and non-primary storage (backups, audit, exception or troubleshooting logs); temporary files holding cleartext PAN during encryption and decryption are not prohibited. Customized approach objective: PAN held on any storage media is never readable in the clear.

evidence an assessor asks for Data storage inventory mapping each PAN location to its protection method; Encryption, hashing, truncation or tokenization design documentation including algorithms; Sample database and log extracts showing PAN unreadable; Backup and archive encryption evidence; Controls preventing correlation of hashed and truncated values (for example keyed hashing, segregation)

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 90 by the default rule: a sector add-on line. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule