• PCI Security Standards Council adds two new devices to PED program

0 Comments
WAKEFIELD, Mass. — The PCI Security Standards Council, a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (DSS), PCI PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS), has announced the addition of two new payment industry device types to the PED program to strengthen cardholder data security.
 
Unattended payment terminals and hardware (also known as host) security modules now can undergo a rigorous testing and approval program to ensure they comply with industry standards for securing sensitive payment card data during any point in the transaction process. The Council also will maintain the list of approved UPTs and HSMs, provide documentation and training for labs evaluating these devices and be a single source of information for device vendors and their customers.
The PED Security Requirements are designed to ensure the security of PIN-based transactions globally and apply to devices that accept PIN entry. Until now, the requirements focused on traditional point-of-sale devices that operate in an environment that is attended by a merchant, cashier or sales clerk. UPTs are unattended payment devices that include self-service ticketing machines, kiosks, automated fuel pumps and vending machines. Vendors have been manufacturing and having the encrypting PIN pads (EPPs) that go into UPTs evaluated by approved labs, and the payment card brands have been requiring the use of PCI SSC approved EPPs. Having new and overarching UPT testing requirements will further protect the payment card industry participants.
 
HSMs are secure cryptographic devices that can be used for PIN translation, card personalization, electronic commerce or data protection and do not include any type of cardholder interface. The addition of UPTs and HSMs into the PCI SSC security testing requirements enables the Council to provide testing laboratories with a streamlined evaluation process for achieving compliance of these cryptographic devices. "PIN entry devices go well beyond the typical POS terminals we are all familiar with and we are continually expanding into more and more areas," said Bob Russo, general manager of the PCI Security Standards Council. "Any device that processes personal identification numbers is an important link in the transaction chain. By including both UPTs and HSMs in the PED Security Requirements, the Council is reaffirming its commitment to developing additional standards to meet the needs of the industry and to ensure continued safety and security for consumers."

Related Content

Reader Comments

Add a Comment

We welcome your thoughtful comments. All comments will display your real name.

Want to participate in the discussion?

Or log in for complete access.

  • Clear
  • Post
Be the first to post a comment for this story.
Products & Services

Virtual ReceptionKiosk Solution

http://global.networldalliance.com/new/images/products/3786.png

3786/Virtual-ReceptionKiosk-Solution

Celsius Outdoor Kiosks

http://global.networldalliance.com/new/images/products/3792.png

3792/Celsius-Outdoor-Kiosks

CUSTOM's PTR80 - Ticket dispenser

http://global.networldalliance.com/new/images/products/PTR80_100px.jpg

3313/CUSTOM-s-PTR80-Ticket-dispenser

Project Management

http://global.networldalliance.com/new/images/products/4094.png

4094/Project-Management

Personal Health Station Kiosk

http://global.networldalliance.com/new/images/products/3785.png

3785/Personal-Health-Station-Kiosk

LG M6503CCBA - 65" class (64.5" measured diagonally)

http://global.networldalliance.com/new/images/products/4307.png

4307/LG-M6503CCBA-65-class-64-5-measured-diagonally

Single Hopper Card Dispenser, SCT3Q8

http://global.networldalliance.com/new/images/products/SCT3Q8_3A0241_100.gif

2931/Single-Hopper-Card-Dispenser-SCT3Q8

Custom's MICROPLAYER

http://global.networldalliance.com/new/images/products/4451.png

4451/Custom-s-MICROPLAYER

Healthcare KIOSKS

http://global.networldalliance.com/new/images/products/4619.png

4619/Healthcare-KIOSKS

CUSTOM's KPM216H II - A4/US letter document size kiosk printer

http://global.networldalliance.com/new/images/products/KPM216HII_100px.jpg

2199/CUSTOM-s-KPM216H-II-A4-US-letter-document-size-kiosk-printer

Customer Experience Technology Buyer
Self-Service Future Trends 2011
Request Information From Suppliers
Save time looking for suppliers. Complete this form to submit a Request for Information to our entire network of partners.