4.2.2—PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies.
>Requirement Description
PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies. Applicability Notes This requirement also applies if a customer, or other third-party, requests that PAN is sent to them via end-user messaging technologies. There could be occurrences where an entity receives unsolicited cardholder data via an insecure communication channel that was not intended for transmissions of sensitive data. In this situation, the entity can choose to either include the channel in the scope of their CDE and secure it according to PCI DSS or delete the cardholder data and implement measures to prevent the channel from being used for cardholder data.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.