Under active development Content is continuously updated and improved

4.2.2PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies.

>Requirement Description

PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies. Applicability Notes This requirement also applies if a customer, or other third-party, requests that PAN is sent to them via end-user messaging technologies. There could be occurrences where an entity receives unsolicited cardholder data via an insecure communication channel that was not intended for transmissions of sensitive data. In this situation, the entity can choose to either include the channel in the scope of their CDE and secure it according to PCI DSS or delete the cardholder data and implement measures to prevent the channel from being used for cardholder data.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.