IBM Mainframe Forum Index
 
Log In
 
IBM Mainframe Forum Index Mainframe: Search IBM Mainframe Forum: FAQ Register
 

PCI#DSS issues


IBM Mainframe Forums -> All Other Mainframe Topics
Post new topic   Reply to topic
View previous topic :: View next topic  
Author Message
haimzeevi

New User


Joined: 01 Mar 2010
Posts: 27
Location: Israel

PostPosted: Tue Jan 18, 2011 5:50 pm
Reply with quote

Regarding requirement, PVV & CVV should be erased from TRK2 info.
Is it mandatory, in all organizations, to erase this info from all backups, as well?
Thanks,
Haim Zeevi
Back to top
View user's profile Send private message
Robert Sample

Global Moderator


Joined: 06 Jun 2008
Posts: 8696
Location: Dubuque, Iowa, USA

PostPosted: Tue Jan 18, 2011 6:37 pm
Reply with quote

Check the manual on PCI compliance.
Back to top
View user's profile Send private message
Bill O'Boyle

CICS Moderator


Joined: 14 Jan 2008
Posts: 2501
Location: Atlanta, Georgia, USA

PostPosted: Tue Jan 18, 2011 6:52 pm
Reply with quote

Haim,

IMHO, it couldn't hurt to re-initialize these values to X'00's.

Also, Track1 Data (BIT 045) should be considered as well.

While you're at it, to be absolutely sure, re-initialize BIT 052 (Pin Block Data) to X'00's (if present).

Welcome to the forum....

Regards,

Bill
Back to top
View user's profile Send private message
haimzeevi

New User


Joined: 01 Mar 2010
Posts: 27
Location: Israel

PostPosted: Wed Jan 19, 2011 3:58 am
Reply with quote

Thank you both.
Robert, we know here what RTFM stands for... but here, PCI requirements got different explanations, depends on whom you ask.
My question was posted to find out about the backups long time backwards.
Thanks again,
Haim.
Back to top
View user's profile Send private message
Robert Sample

Global Moderator


Joined: 06 Jun 2008
Posts: 8696
Location: Dubuque, Iowa, USA

PostPosted: Wed Jan 19, 2011 5:02 am
Reply with quote

Quote:
but here, PCI requirements got different explanations, depends on whom you ask.
Not according to www.pcisecuritystandards.org they don't. I got pulled into some PCI compliance things a while back and learned to read the official PCI documentation. If you're dealing with PCI issues, you need to learn what the documentation tells you as well. Don't rely on what people tell you -- sometimes interpretations may not be accurate, or be in conflict (as apparently you've found out).

Short answer: card number and CVV (for one) cannot be stored clear text anywhere. This includes disk, tape, backups, VSAM files, servers, you name it. I was working with PCI DSS 1.1 so I'm not sure how much it has changed with the latest standard (probably not a lot in this area), but PCI compliance for 1.1 did not permit storage of the CVV after authentication was done -- period. Encryption did not matter; the CVV was not allowed to be stored at all.
Back to top
View user's profile Send private message
haimzeevi

New User


Joined: 01 Mar 2010
Posts: 27
Location: Israel

PostPosted: Wed Jan 19, 2011 3:28 pm
Reply with quote

Thanks for both answer & PCI link.
The answer was "loud & clear"....
Haim Zeevi
Back to top
View user's profile Send private message
Robert Sample

Global Moderator


Joined: 06 Jun 2008
Posts: 8696
Location: Dubuque, Iowa, USA

PostPosted: Wed Jan 19, 2011 3:54 pm
Reply with quote

Glad to hear it helped! icon_smile.gif
Back to top
View user's profile Send private message
View previous topic :: :: View next topic  
Post new topic   Reply to topic View Bookmarks
All times are GMT + 6 Hours
Forum Index -> All Other Mainframe Topics

 


Similar Topics
Topic Forum Replies
No new posts Issues Converting From ZD to Signed N... DFSORT/ICETOOL 4
No new posts Issues with VIEW DATASET Command CLIST & REXX 2
No new posts Issues with executing a REXX MACRO th... TSO/ISPF 4
No new posts Issues with outrec overlay while extr... SYNCSORT 7
No new posts Large'ish Working Storage and SOS issues CICS 0
Search our Forums:

Back to Top