Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Common, but Easily Avoidable, PCI DSS Compliance Miscues current page
Link copied

Common, but Easily Avoidable, PCI DSS Compliance Miscues

Jul 15, 2019
Author:
Ben Rothke Bio Pic
Ben Rothke
Senior Security Consultant, Nettitude
Blog banner default
Common, but Easily Avoidable, PCI DSS Compliance Miscues
Ben Rothke Bio Pic
Ben Rothke
Senior Security Consultant, Nettitude

I spent many years as PCI QSA, and my recent webinar: The PCI DSS Compliance Essentials: Top 10 Things You Need to Know tried to encapsulate some of the most important areas firms need to consider as they go down the road to PCI compliance. Perhaps the most important topic I covered in the webinar is one that far too many firms don’t even consider—asking why they even store PCI cardholder data (CHD) in the first place.

A lot of firms accept as a fact of doing business that they need to store CHD. The reality is that, for most organizations, there is no compelling business or technology reason for retaining cardholder data. In 2019, there are plenty of vendors who offer tokenization solutions that merchants and service providers can use to ensure that they never see customer CHD. Instead, they only will use the tokens, which are data strings that are out of scope for PCI.

By using tokenization, firms can significantly limit their PCI scope and responsibilities, and risk of damaging data loss or exposure. This, in turn, results in significant cost savings, and many less hours required toward PCI compliance.

Besides tokenization, there are other potential solutions, such as credit card vaulting, point-to-point encryption (P2PE), and end-to-end encryption (E2EE). Whichever solution you consider, the goal is to start thinking about how you can get out of the CHD storage business.

Another important area is that of scoping. The first step of PCI DSS is to accurately determine the scope of the environment. As detailed in the PCI DSS Quick Reference Guide, the scoping process includes identifying all system components that are located within, or connected to, the cardholder data environment. The cardholder data environment is comprised of people, processes, and technology that handle cardholder data or sensitive authentication data.

Yet, too many firms don’t invest enough time in the scoping process. This can be a significant issue, as if a firm over-scopes, they will end up exerting unnecessary time, effort, and expenses. On the other hand, if they under-scope and exclude things that are truly within scope, the outcome is that they are not PCI compliant, and all of the fallout that entails.

Another major PCI violation that organizations commonly commit is the unneccessary storing of sensitive authentication data (SAD). PCI defines SAD as security-related information—including, but not limited to, card validation codes/values, full track data (from the magnetic stripe or equivalent on a chip, PINs, and PIN blocks) used to authenticate cardholders and/or authorize payment card transactions. SAD can never be stored after authentication.

Being educated about the PCI DSS requirements is your best method to ensure compliance, minimize costs, and ensure that you are fully compliant with PCI DSS. For more education that will help poise you for success with PCI, check out my on-demand webinar.

Latest Posts
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
Related
  • The Clock Strikes 13 on the 2020 Verizon Data Breach Investigations Report
    May 29, 2020 The Clock Strikes 13 on the 2020 Verizon Data Breach Investigations Report
    Blog
    1m
  • Innovating for Identity: How BeyondTrust Navigates Today's Cybersecurity Landscape
    Dec 27, 2023 Innovating for Identity: How BeyondTrust Navigates Today's Cybersecurity Landscape
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.