Edge Rewrite
Jump to content

Talk:Payment Card Industry Data Security Standard

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 4 months ago by ~2026-21336-26 in topic Proposed section: Telephone and call centre compliance

Removal of section "Risk management to protect cardholder data"

[edit]

While I generally try to WP:BEBOLD, I think the removal of this section requires some notice. There's a number of problems with the inclusion of this section that, in my opinion, warrant full removal. Absent any other comments, I will eventually remove this. Here's my justification.

The section starts talking about risk management. Risk management programs are defined under requirement 12, but instead the article discusses requirement 3, which is about controls protecting *stored* data. It also seems to be fixated on HSMs, which are are relevant generally for PCI, but are not discussed at all in the PCI DSS. Finally, the risk management "steps" do not coincide remotely with what exist under the req 12 risk management processes.

Those are the basic problems with what exists currently.

But in the end, the larger reason I think this should be removed, is that it picks one/two specific detailed areas to focus on in terms of the actual requirements, while the rest of the article only discusses high-level issues. From my standpoint, it's not feasible (without more editor interest) to get into detailed discussions about particular PCI DSS requirements, so we should stick with a high-level discussion instead.

DoubleRelevance (talk) 07:24, 15 August 2023 (UTC)Reply

The lack of independent sourcing makes the section even more dubious. — BillHPike (talk, contribs) 17:54, 17 August 2023 (UTC)Reply
I've gone ahead and removed the section. I'll also comment, sourcing is a problem with this topic in general, because essentially you can only find primary sources or non-independent secondary sources for support of the content. The PCI Council promulgates the rules, and certifies companies to be authorities on the interpretation of the rules (though card brands and merchant banks are also authorities). So under Wikipedia rules, most secondary sources get reverted immediately for not being independent. Which I'm not saying is bad or wrong, it's just an unfortunate effect of the system under which the PCI DSS operates. DoubleRelevance (talk) 02:57, 2 September 2023 (UTC)Reply

Wiki Education assignment: Social Informatics - ITI 547-200 Section 07

[edit]

This article was the subject of a Wiki Education Foundation-supported course assignment, between 4 September 2025 and 10 December 2025. Further details are available on the course page. Student editor(s): Leaves.of.Three (article contribs).

— Assignment last updated by NicholasJohnstoneNMJ83 (talk) 22:47, 22 October 2025 (UTC)Reply

Proposed section: Telephone and call centre compliance

[edit]

Hello,

 I noticed that the French Wikipedia article on PCI DSS ([[:fr:Norme de sécurité de   
 l'industrie des cartes de paiement|fr:Norme de sécurité de l'industrie des cartes de
 paiement]], section 7.2) covers call centre security and DTMF masking as a compliance
  topic, but the English article has no equivalent section.
 Telephone-based card payments are a significant area of PCI DSS compliance — the PCI 
 Security Standards Council has published specific guidance on protecting
 telephone-based payment card data, and DTMF masking technology is widely deployed    
 across contact centre environments.
 I'd like to propose adding a subsection on telephone and call centre compliance,     
 covering:
                                                                                      
 * PCI SSC guidance on call recordings containing cardholder data                     
 * Technical approaches to scope reduction (IVR, DTMF masking, pause-and-resume)
 * How channel separation and DTMF suppression affect self-assessment scope           
                                                                                      
 === Proposed draft text ===                                                          
                                                                                      
 Organisations that accept payment card data over the telephone face specific PCI DSS 
 compliance challenges, as call recordings, agent workstations, and telephony
 infrastructure may all come into contact with cardholder data. The PCI Security      
 Standards Council has issued guidance noting that digital call recordings containing
 sensitive authentication data must not be stored after authorisation, regardless of
 encryption method used.
 Several technical approaches have been developed to reduce PCI DSS scope in telephone
  payment environments:
                                                                                      
 * Interactive voice response (IVR): Calls are transferred to an automated      
 system for card data entry, removing agents from the payment flow entirely. This
 approach eliminates agent exposure to cardholder data but interrupts the             
 customer–agent interaction.
 * DTMF masking: Customers enter card details using their telephone keypad while
  remaining on the call with an agent. The dual-tone multi-frequency (DTMF) signals
 are intercepted and replaced with flat tones in real time, preventing the agent or   
 call recording systems from capturing the card data. The payment data is routed
 directly to a payment processor through a separate channel.
 * Pause and resume: Call recording is manually or automatically paused while   
 the customer provides card details, then resumed. This reduces recording exposure but
  does not prevent agent access to spoken card data.                                  
                 
 The use of DTMF masking and channel separation technologies can allow organisations  
 to reduce their PCI DSS self-assessment scope, as cardholder data does not enter the
 merchant's environment.                                                              
                 
 === References ===
 All statements can be sourced from PCI Security Standards Council publications       
 including the Information Supplement on Protecting Telephone-Based Payment Card Data
 and PCI DSS v4.0 Requirement 3.                                                      
                 
 Disclosure: I work for a company that operates in the telephone payment        
 security space. I am proposing this content for editorial review rather than adding
 it directly, per WP:COI guidelines. Curtlondon (talk) 13:47, 6 April 2026 (UTC)Reply
@Curtlondon: We are highly unlikely to add text that has come directly from an AI chatbot. Sorry. • a frantic turtle 🐢 14:12, 6 April 2026 (UTC)Reply
Oh dear, I did not realise there was a ban on AI content even if it factually correct and helps someone. ~2026-21336-26 (talk) 10:35, 7 April 2026 (UTC)Reply