A security architect is tasked with implementing data security for a new application that processes credit card information. To achieve PCI DSS compliance, the architect needs to ensure that sensitive authentication data (SAD) is never stored after authorization, even if encrypted. Which data security control BEST addresses this specific requirement?
- ATokenization
- BData Minimization
- CFormat-Preserving Encryption (FPE)
- DData Masking
Show answer & explanationAnswer & explanation
Correct answer: A. Tokenization
Tokenization replaces sensitive data (like primary account numbers or SAD) with a non-sensitive equivalent (a token) that has no exploitable meaning or value. For PCI DSS, specifically, SAD must not be stored after authorization, even if encrypted. Tokenization achieves this by ensuring the original SAD is never stored by the merchant system, only a non-sensitive token, and the actual SAD is held in a secure, compliant token vault.
Why the other options are wrong
- B. Data minimization is a broader principle of collecting and retaining only necessary data. While good practice, it doesn't specifically address the technical control for handling SAD that must not be stored at all after authorization.
- C. FPE encrypts sensitive data while preserving its original format. However, it still means the encrypted original data is stored, which is explicitly prohibited for SAD after authorization by PCI DSS, even if encrypted.
- D. Data masking obscures sensitive data by replacing it with realistic but false data. While useful for non-production environments, it typically still involves storing a form of the original sensitive data, which is not allowed for SAD after authorization.
Tokenization for PCI DSS SAD
Tokenization is a data security technique where sensitive data (like credit card numbers or Sensitive Authentication Data - SAD) is replaced with a unique, non-sensitive identifier called a token. For PCI DSS, this ensures SAD is never stored by the merchant after authorization, as only the token is retained.
- Replaces sensitive data with a non-sensitive token.
- Original data stored in a secure token vault (or discarded for SAD).
- Crucial for PCI DSS compliance, especially for SAD.
- Reduces the scope of PCI DSS for systems handling tokens.
- Protects against breaches as tokens have no intrinsic value.
Memory trick: Don't keep the real card details, just a fake ID.