SecurityCRunch is dedicated to the IT Security Industry. Questions - Send an email to : greg@securitycrunch.com
Pass this site onto your Security Friends!! Bookmark and Share
0

Q: Can the full credit card number be printed on the consumer’s copy of the receipt?

flag

3 Answers

0

That would not be a question of PCI compliance per-se. PCI-DSS is concerned with electronic data storage and retrieval, not printed records. Having said that, it's always good to mask the card number when it's not required. PCI-DSS allows the first six and last four digits to be stored unencrypted (not considered a usable/guessable card number at that point). You could use that as a starting point for what's appropriate, but many merchants just print the last four digits and mask the rest.

link|flag
0

That is not a PCI compliance issue. FACTA compliance says that it can't be on the consumer copy, at least within the US.

link|flag
0

PCI audit testing procedures:

"3.3 Obtain and examine written policies and examine displays of PAN (for example, on screen, on paper receipts) to verify that primary account numbers (PANs) are masked when displaying cardholder data, except for those with a legitimate business need to see full PAN.

(This requirement does not supersede stricter requirements in place for displays of cardholder data—for example, for point-of-sale (POS) receipts.)"

"9.6 Verify that procedures for protecting cardholder data include controls for physically securing paper and electronic media (including computers, removable electronic media, networking, and communications hardware, telecommunication lines, paper receipts, paper reports, and faxes)."

link|flag

Your Answer

Get an OpenID
or

Not the answer you're looking for? Browse other questions tagged or ask your own question.