Talk:Payment Card Industry Data Security Standard
Add topic| This article is rated Start-class on Wikipedia's content assessment scale. It is of interest to the following WikiProjects: | |||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||
Archives (Index) |
|
This page is archived by ClueBot III. |
Removal of section "Risk management to protect cardholder data"
[edit]While I generally try to WP:BEBOLD, I think the removal of this section requires some notice. There's a number of problems with the inclusion of this section that, in my opinion, warrant full removal. Absent any other comments, I will eventually remove this. Here's my justification.
The section starts talking about risk management. Risk management programs are defined under requirement 12, but instead the article discusses requirement 3, which is about controls protecting *stored* data. It also seems to be fixated on HSMs, which are are relevant generally for PCI, but are not discussed at all in the PCI DSS. Finally, the risk management "steps" do not coincide remotely with what exist under the req 12 risk management processes.
Those are the basic problems with what exists currently.
But in the end, the larger reason I think this should be removed, is that it picks one/two specific detailed areas to focus on in terms of the actual requirements, while the rest of the article only discusses high-level issues. From my standpoint, it's not feasible (without more editor interest) to get into detailed discussions about particular PCI DSS requirements, so we should stick with a high-level discussion instead.
DoubleRelevance (talk) 07:24, 15 August 2023 (UTC)
- The lack of independent sourcing makes the section even more dubious. — BillHPike (talk, contribs) 17:54, 17 August 2023 (UTC)
- I've gone ahead and removed the section. I'll also comment, sourcing is a problem with this topic in general, because essentially you can only find primary sources or non-independent secondary sources for support of the content. The PCI Council promulgates the rules, and certifies companies to be authorities on the interpretation of the rules (though card brands and merchant banks are also authorities). So under Wikipedia rules, most secondary sources get reverted immediately for not being independent. Which I'm not saying is bad or wrong, it's just an unfortunate effect of the system under which the PCI DSS operates. DoubleRelevance (talk) 02:57, 2 September 2023 (UTC)
Wiki Education assignment: Social Informatics - ITI 547-200 Section 07
[edit]
This article was the subject of a Wiki Education Foundation-supported course assignment, between 4 September 2025 and 10 December 2025. Further details are available on the course page. Student editor(s): Leaves.of.Three (article contribs).
— Assignment last updated by NicholasJohnstoneNMJ83 (talk) 22:47, 22 October 2025 (UTC)
Proposed section: Telephone and call centre compliance
[edit]Hello,
I noticed that the French Wikipedia article on PCI DSS ([[:fr:Norme de sécurité de l'industrie des cartes de paiement|fr:Norme de sécurité de l'industrie des cartes de paiement]], section 7.2) covers call centre security and DTMF masking as a compliance topic, but the English article has no equivalent section.
Telephone-based card payments are a significant area of PCI DSS compliance — the PCI Security Standards Council has published specific guidance on protecting telephone-based payment card data, and DTMF masking technology is widely deployed across contact centre environments.
I'd like to propose adding a subsection on telephone and call centre compliance,
covering:
* PCI SSC guidance on call recordings containing cardholder data
* Technical approaches to scope reduction (IVR, DTMF masking, pause-and-resume)
* How channel separation and DTMF suppression affect self-assessment scope
=== Proposed draft text ===
Organisations that accept payment card data over the telephone face specific PCI DSS
compliance challenges, as call recordings, agent workstations, and telephony
infrastructure may all come into contact with cardholder data. The PCI Security
Standards Council has issued guidance noting that digital call recordings containing
sensitive authentication data must not be stored after authorisation, regardless of
encryption method used.
Several technical approaches have been developed to reduce PCI DSS scope in telephone
payment environments:
* Interactive voice response (IVR): Calls are transferred to an automated
system for card data entry, removing agents from the payment flow entirely. This
approach eliminates agent exposure to cardholder data but interrupts the
customer–agent interaction.
* DTMF masking: Customers enter card details using their telephone keypad while remaining on the call with an agent. The dual-tone multi-frequency (DTMF) signals are intercepted and replaced with flat tones in real time, preventing the agent or call recording systems from capturing the card data. The payment data is routed directly to a payment processor through a separate channel.
* Pause and resume: Call recording is manually or automatically paused while
the customer provides card details, then resumed. This reduces recording exposure but
does not prevent agent access to spoken card data.
The use of DTMF masking and channel separation technologies can allow organisations
to reduce their PCI DSS self-assessment scope, as cardholder data does not enter the
merchant's environment.
=== References ===
All statements can be sourced from PCI Security Standards Council publications
including the Information Supplement on Protecting Telephone-Based Payment Card Data
and PCI DSS v4.0 Requirement 3.
Disclosure: I work for a company that operates in the telephone payment
security space. I am proposing this content for editorial review rather than adding
it directly, per WP:COI guidelines. Curtlondon (talk) 13:47, 6 April 2026 (UTC)
- @Curtlondon: We are highly unlikely to add text that has come directly from an AI chatbot. Sorry. • a frantic turtle 🐢 14:12, 6 April 2026 (UTC)
- Oh dear, I did not realise there was a ban on AI content even if it factually correct and helps someone. ~2026-21336-26 (talk) 10:35, 7 April 2026 (UTC)
- Start-Class WikiProject Business articles
- Low-importance WikiProject Business articles
- WikiProject Business articles
- Start-Class Computer security articles
- Low-importance Computer security articles
- Start-Class Computer security articles of Low-importance
- Start-Class Computing articles
- Low-importance Computing articles
- All Computing articles
- All Computer security articles
- Start-Class London-related articles
- Low-importance London-related articles
- Start-Class Finance & Investment articles
- Mid-importance Finance & Investment articles
- WikiProject Finance & Investment articles
