
【国外标准】 Retail Financial Services - Requirements for Protection of Sensitive Payment Card Data - Part 1: Using Encryption Method
本网站 发布时间:
2023-03-28
开通会员免费在线看70000余条国内标准,赠送文本下载次数,单本最低仅合13.3元!还可享标准出版进度查询、定制跟踪推送、标准查新等超多特权!  
查看详情>>

适用范围:
Theft of sensitive card data during a retail payment transaction is increasingly becoming a major source of financial fraud. Besides an optional encrypted PIN, this data includes magnetic stripe track 2 data: PAN, expiration date, card verification value, and issuer private data. While thefts of this data at all segments of the transaction processing system have been reported, the most vulnerable segments are between the point of transaction device capturing the magnetic stripe data and the processing systems at the acquirer. This document would standardize the security requirements and implementation for a method for protecting this sensitive card data over these segments. Several implementations exist to address this situation. This document would provide guidance for evaluating these implementations. Clarification based on card brand guidance for the encryption of the middle digits has been added to this document. This supports the automated fuel dispenser industry.
标准号:
ANSI X9.119-1-2016
标准名称:
Retail Financial Services - Requirements for Protection of Sensitive Payment Card Data - Part 1: Using Encryption Method
英文名称:
Retail Financial Services - Requirements for Protection of Sensitive Payment Card Data - Part 1: Using Encryption Method标准状态:
现行-
发布日期:
-
实施日期:
出版语种:
- 推荐标准
- ANSI INCITS 135-1992 (R1998) Information Systems - Database Language - SQL (includes ANSI X3.168-1989) (formerly ANSI X3.135-1992 (R1998))
- ANSI INCITS 189-1991 (R2002) Information Systems - Interface between Data Terminal Equipment (DTE) and Data Circuit-Terminating Equipment (DCE) for Terminals Operating in the Packet Mode and Accessing a Packet-Switched Public Data Network Through Switched Access (formerly ANSI X3.189-1991 (R1997))
- ANSI INCITS 191-1991 (R2002) Recorded Optical Media Unit for Digital Information Interchange - 130-mm Write-Once Sampled-Servo RZ Selectable-Pitch Optical Disk Cartridge (formerly ANSI X3.191-1991 (R1997))
- ANSI INCITS 198-1992 (R2002) Programming Language - Fortran - Extended (formerly ANSI X3.198-1992 (R1997))
- ANSI INCITS 200-1992 (R2002) Information Systems - Unrecorded Optical Media Unit for Digital Information Interchange - 356 mm WORM Optical Disk Cartridge - Parts 1 and 2 (formerly ANSI X3.200-1992 (R1997))
- ANSI INCITS 263-1995 (S2010) Fibre Distributed Data Interface (FDDI) - Token Ring Twisted Pair Physical Layer Medium Dependent (TP-PMD) (formerly INCITS 263-1995 (R2005))
- ANSI INCITS 288-1999 Information Technology - Fibre Channel - Generic Services (FC-GS) (revision and redesignation of ANSI X3.288-1996) (formerly ANSI INCITS 288-1999)
- ANSI INCITS 297-1997 (R2002) Information Technology - Fibre Channel - Physical and Signalling Interface-2 (FC-PH-2) (formerly ANSI X3.297-1997)
- ANSI INCITS 317-1998 (R2008) AT Attachment with Packet Interface Extension (ATA/ATAPI-4)
- ANSI INCITS 326-1999 Information Technology - Fibre Channel - Low-Cost 10-km Optical 1063-MBaud Interface (100-SM-LC-L) (formerly ANSI INCITS 326-1999)
- ANSI INCITS 336-2000 Information Technology - SCSI Parallel Interface-3 (SPI-3) (formerly ANSI INCITS 336-2000)
- ANSI INCITS 349-2001 Information Technology - Fibre Channel - Single-Byte-2 (FC-SB-2) (formerly ANSI INCITS 349-2001)
- ANSI INCITS 351-2001 Information Technology - SCSI Primary Commands - 2 (SPC-2) (formerly ANSI INCITS 351-2001)
- ANSI INCITS 354-2001 Common Industry Format for Usability Test Reports (formerly ANSI INCITS 354-2001)
- ANSI INCITS 355-2001 Information Technology - Fibre Channel Switch Fabric -2 (FC-SW-2) (formerly ANSI INCITS 355-2001)