PCI PIN Security

PCI PIN Security is the Security Standard defined by Visa, MasterCard, JCB, American Express, Discover Card Brands, for entities that participate in processes of Personal Identification Number (PIN) transactions. The most recent version of PCI PIN Security is 3.1.

Do you need PCI PIN Security assessment? Contact us now for inquiry — Quotation Assistance

Overview

What is PCI PIN Security?

In general, organizations or their supporting 3rd parties providing ATM, POS to process PIN transactions need to comply with this standard, including acquirers providing ATM or POS Terminals, Issuers, and intermediate networks (Switch, Network, Card Brands Networks etc.).

According to the requirements of Card Brands, those service vendors providing Key Injection Facilities (KIF) or Certification Authority are subject to a Self-Assessment Questionnaire or a QPA assessment completed by a PCI SSC Qualified PIN Security Assessor (QPA). All acquiring institutions and agents (e.g., key-injection facilities and certificate processors) responsible for PIN transaction processing on the payment card industry participants' denominated accounts should be required to complete a Self-Assessment Questionnaire or complete an audit by a PCI SSC authorized Qualified PIN Security Assessor (QPA).

Learn more at PCI SSC website

PIN Security Compliance Process

To meet PCI PIN Security Compliance requirements, tasks are categorized as follows:

1

Create management procedures

PCI PIN Security requirements are organized into seven related groups, referred to as "Control Objectives". Each control objective requires management of security policy and procedures, including Point of Interaction (POI) management procedures which cover ATM, POS Terminal management, HSM management procedures, and the most important part, Key Management related procedures, including key generation, distribution, rotation, revocation, destruction, key exchange with other organizations management procedures, usages of PIN Blocks and Key Blocks, and appliance physical security.

2

Inventory of Devices, Key, and Exchange Organizations

PIN Security relevant devices should include POI (ATM, POS) devices, HSM Keys, Encryption Devices, Key Loading Devices, Servers, and according Host Software — all should be inventoried and managed. Due to high volumes of POI, loading keys onto devices requires a strict and precise management process to manage organization internal usages of keys, HSM, participants of transactions, key exchange organizations, and lastly inventory management of outsourcing service providers.

3

Operation supervision and management

All devices of POI (ATM, POS), HSM, Servers, usages of Key Loading Devices, records, and inspection management must follow operation guideline procedures and keep decent logging. Key exchanges, Key Loading, and Generation must follow required Dual Control, Split Knowledge, and Monitoring, having records logging with monitoring and reviews.

PIN Security Review Process

I. Gap analysis
II. Consulting
III. Onsite PIN assessment
IV. Changes
V. Audit Completion

I. Gap analysis

Start with Gap analysis, to verify the gaps between the current environment and PCI PIN Security Standard about devices and operations managements, and identify tasks of meeting the compliance requirements.

II. Consulting

Consulting by experienced PCI PIN Security consultants, based on standard requirements to provide technical and management advisory, and help the assessed entity to complete implementations and meet the standard requirements.

III. Onsite PIN assessment

PCI QPA assesses the implementations of the assessed entity against the requirements of PCI PIN Security Standard and according to the frequency required by each Card Brand to complete the assessment results.

IV. Changes

Assessment may result in Non-Compliance findings where the current environment is not compliant with the standard, thus needing the assessed entity to implement remediation, corrections, or technical enhancement, changes in processing flows. Upon implementing remediation with implementation evidence complete, obtain another onsite assessment or evidence reviews by QPA to validate the compliance to the standard.

V. Audit Completion

The ROC is effectively a summary of evidence derived from the assessor's work papers to describe how the assessor performed the validation activities and how the resultant findings were reached. At a high level, the ROC provides a comprehensive summary of testing activities performed and information collected during the assessment against the PCI PIN Security Requirements and Test Procedures. When all Non-Compliance items are fixed and validated, PCI QPA will issue the assessment reports, including Report on Compliance (ROC) and Attestation of Compliance (AOC). The assessment is completed when the assessed entity signs and accepts the AOC report.

Want to know more about PCI PIN Security Assessment?

Don't Hesitate to Contact us!