No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Latest Industry News

Merchant Account

Credit Card Processing

Point-of-Sale Terminals

Security and Fraud

Press Releases


Get a Rate Quote
Call Us Today
Find us on Facebook

Industry News

PCI SSC changes rules regarding audio recordings of payment processing data

By Kristen Lawrence

03/02/2010 - The PCI Security Standards Council has updated its FAQ section, changing the rules regarding payment processing information stored on audio recordings.

StorefrontBacktalk.com reported that the rules, which mostly apply to call centers, now require cardholder data contained on an audio record to be subject to the same rules used for cardholder data stored in written form.

The new FAQ reports that "it is a violation of PCI DSS requirement 3.2 to store any sensitive authentication data, including card validation codes and values, after authorization, even if encrypted," StorefrontBacktalk.com cited. "It is therefore prohibited to use any form of digital audio recording (using formats such as wav, mp3, etc.) for storing CAV2, CVC-2, CVV-2 or CID codes after authorization, as card data can easily be extracted using freely available software."

However, the website also reports that this would not solve the payment processing security threat of audio recording on the consumer side - one tactic hackers are using is to call a company with a long list of questions, record the call, and then play it back to catch credit card information being spoken by other call operators in the background. To combat this, companies may want to invest in sound-proof cubicle dividers.

The PCI DSS is a continually changing set of regulations - it is currently undergoing a major revision by the PCI Security Standards Council - so businesses with merchant accounts are advised to stay updated on its rules and guidelines.ADNFCR-2514-ID-19596313-ADNFCR

Related News - Security and Fraud

Cloud computing and payment processing security: Not mutually exclusive after all?

19/03/2010

With cloud computing becoming a more and more popular and attractive IT model for organizations, one serious concern that has arisen is what the implications are for PCI compliance and overall payment processing security.

Full Article

Discovered chip and pin exploit may not pose significant real-world threat to payment processing security

19/03/2010

The recent report from Cambridge University researchers showing the vulnerability of the chip card payment processing system to fraud may not have that many real-world consequences, said the Financial Post.

Full Article

PCI DSS compensating controls are not shortcuts, experts remind businesses

18/03/2010

Many businesses think of compensating controls as a shortcut to payment processing compliance. However, compensating controls in reality are nothing near a shortcut - they require research and analysis to correctly implement.

Full Article

PCI SSC: Level 4 merchants shouldn't hold breath for tiered payment processing security requirements

16/03/2010

A common complaint among small, Level 4 merchants is that the PCI compliance mandates are too intense and burdensome for them, and are better suited to larger merchants.

Full Article