Cardholder data and PCI DSS: the clause the question tests
Whether card data passes through the service, and on what PCI DSS attestation.
How the customer usually asks it
example"Do you store, process or transmit cardholder data?"
Anchor clauses
1 framework| Framework | Anchor clause |
|---|---|
| PCI DSS v4.0.1 | 3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following · 12.5.2 PCI DSS scope documented and confirmed annually |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The PCI DSS attestation of compliance or self-assessment for the service, with its scope, and the data flow showing where account data goes.
The clauses, with what an assessor asks for
PCI DSS 3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the followingWhat it asks for, in one line (the standard's own text is not quoted here):
Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following:; Coverage for all locations of stored account data.
Where answers usually fall short: Indefinite retention by default; No deletion proof
Source: PCI DSS v4.0.1
PCI DSS 12.5.2 PCI DSS scope documented and confirmed annuallyWhat it asks for, in one line (the standard's own text is not quoted here):
PCI DSS scope is documented and confirmed at least once every 12 months by identifying all data flows, system components, and segmentation controls in use.
Where answers usually fall short: Diagrams stale; Annual scoping skipped
Source: PCI DSS v4.0.1