What is end-to-end encryption in payment processing?
- A.Only encrypting the payment gateway, which the standard's glossary defines broadly enough that any reversible encoding, including Base64, qualifies as strong cryptography provided the encoding scheme is kept confidential
- B.Encryption that protects cardholder data from the point of capture (e.g., card reader) all the way to the processing endpoint, without decryption at intermediate points
- C.Encrypting backup tapes, given that disk-level encryption alone satisfies the requirement to render the primary account number unreadable for encrypted PAN held at rest
- D.Encrypting only the database, as the standard permits account data to be sent over wireless without any encryption for service providers once the CDE has been segmented
Why B is correct
End-to-end encryption protects data from capture point to processing destination, keeping it encrypted throughout all intermediate stages.
Know someone studying for PCI DSS? Send them this one.