Protect Account Data
4
Protect Cardholder Data with Strong Cryptography During Transmission
Cardholder data transmitted over open, public networks must be encrypted with strong cryptography. This requirement covers all transmission channels including internet, wireless, cellular, satellite, and any other open network. It also applies to PAN sent via end-user messaging technologies.
Control Intent
Prevent interception and compromise of cardholder data during transmission over networks that are easily accessible to malicious individuals, by applying current strong cryptographic protocols.
Common Failures
- Using outdated or vulnerable protocols such as SSL, TLS 1.0, or early TLS 1.1 for data transmission
- Sending PAN in plain text via email or other end-user messaging channels
- Expired or self-signed SSL/TLS certificates on public-facing payment pages
- Failure to disable fallback to insecure protocols, allowing protocol downgrade attacks
- Missing encryption on internal network segments where cardholder data traverses between systems