What does PCI DSS mean by 'strong cryptography'?
- A.Only military-grade encryption, given that the standard requires strong cryptography only for data leaving the entity's premises for Level 4 merchants
- B.Encryption with short keys, addressed by Requirement 3.6 through documented key-management policies that cover the full lifecycle of the keys protecting stored account data
- C.Cryptography based on industry-tested and accepted algorithms with sufficient key lengths, such as AES-128 or higher, along with proper key management
- D.Any encryption method, because the standard treats an unkeyed hash of the primary account number as strong cryptography for encrypted PAN held at rest
Why C is correct
Strong cryptography uses industry-tested algorithms like AES with key lengths of 128 bits or higher, combined with proper key management practices.
Know someone studying for PCI DSS? Send them this one.