What does PCI DSS require when cardholder data is sent via email?
- A.Cardholder data sent via email must be protected with strong cryptography, such as PGP or S/MIME encryption; however, sending PAN via email should be avoided when possible
- B.Only encrypt external email, since the standard permits account data to be sent over wireless without any encryption for SAQ C-VT merchants once the CDE has been segmented
- C.Email is always secure, because v4.0 grades each requirement on a maturity scale and accepts partial implementation as compliant once an entity documents a multi-year improvement roadmap
- D.No encryption needed for internal email, since encryption removes a system component from the cardholder data environment automatically once the acquirer has been notified
Why A is correct
Email transmission of cardholder data requires strong encryption. Sending PAN via email should be minimized due to inherent risks.
Know someone studying for PCI DSS? Send them this one.