PCI Data Security Standard
The Payment Card Industry Data Security Standard is a set of comprehensive requirements for enhancing payment account data security. The PCI DSS includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.
Requirement 3: Protect stored cardholder data
Encryption is a critical component of cardholder data protection. If an intruder circumvents other network
security controls and gains access to encrypted data, without the proper cryptographic keys, the data is
unreadable and unusable to that person. Other effective methods of protecting stored data should be
considered as potential risk mitigation opportunities. For example, methods for minimizing risk include not
storing cardholder data unless absolutely necessary, truncating cardholder data if full PAN is not needed,
and not sending PAN in unencrypted e-mails.
Stated in this set of standards, encryption is a critical component to protecting customer data. BOSaNOVA's Q3 storage encryption solution assists in your compliance with the PCI Standard by protecting your customer's data with encryption. The Q3 storage security appliance encrypts data at rest without effecting your current backup procedures. Installation is quick and key management is strong yet simple.
For more information please contact us at 800-866-6267 or info@bosanova.net