As a QSA, one should always ask the clients to store truncated PAN and hashed value separately and use a salted hash.
Per PCI DSS Requirement 3.4e, if the hashed PAN and Truncated PAN of the same credit/debit card number exists in the same environment, then there must be additional security controls present to prevent the reconstruction of original PAN.
These QSA’s perform comprehensive PCI compliance assessments that relate to the protection of customer SAD such as PAN. To know more about protecting cardholder data and PCI DSS certification, visit our PCI DSS Certification page.
Credits:
Varun Kaushik
VP - APAC Continuous Compliance, ControlCase.
As a QSA, one should always ask the clients to store truncated PAN and hashed value separately and use a salted hash.
Per PCI DSS Requirement 3.4e, if the hashed PAN and Truncated PAN of the same credit/debit card number exists in the same environment, then there must be additional security controls present to prevent the reconstruction of original PAN.
These QSA’s perform comprehensive PCI compliance assessments that relate to the protection of customer SAD such as PAN. To know more about protecting cardholder data and PCI DSS certification, visit our PCI DSS Certification page.
Credits:
Varun Kaushik
VP - APAC Continuous Compliance, ControlCase.