by Froga
How a card number is protected in storage, at the terminal, and at checkout -- PCI DSS, tokenization, EMV chips, and 3-D Secure, tied back to the encryption and certificates covered earlier in this path.
Payment security overlaps with general web security but is not the same problem. A TLS connection (covered elsewhere in this path) protects data in transit, between a shopper's browser and a merchant's server. But a card number is valuable long after that connection closes -- it can be charged again, sold, or used somewhere else entirely. That is why payment security also covers how card data is stored, how long it is kept, who is allowed to see it, and what a business has to prove about all of that. The rules that formalize this are the Payment Card Industry Data Security Standard (PCI DSS), which applies to any business that stores, processes, or transmits card data -- not just banks.
multiple choice
Ready to test yourself?
Sign up free to answer, score points, and build your streak.