Skip to main content

💼 3.3.1 SAD is not retained after authorization, even if encrypted.

  • ID: /frameworks/pci-dss-v4.0.1/03/03/01

Description

All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process.

Similar

  • Sections
    • /frameworks/pci-dss-v4.0/03/03/01

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v4.0 → 💼 3.3.1 SAD is not retained after authorization, even if encrypted.35no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v4.0 → 💼 3.3.1 SAD is not retained after authorization, even if encrypted.35no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 3.3.1.1 The full contents of any track are not stored upon completion of the authorization process.no data
💼 3.3.1.2 The card verification code is not stored upon completion of the authorization process.no data
💼 3.3.1.3 The personal identification number (PIN) and the PIN block are not stored upon completion of the authorization process.no data

Policies (5)

PolicyLogic CountFlagsCompliance
🛡️ Google BigQuery Dataset is not encrypted with Customer-Managed Encryption Key (CMEK)🟢1🟢 x6no data
🛡️ Google BigQuery Table is not encrypted with Customer-Managed Encryption Key (CMEK)🟢1🟢 x6no data
🛡️ Google Dataproc Cluster is not encrypted using Customer-Managed Encryption Key🟢1🟢 x6no data
🛡️ Google GCE Disk for critical VMs is not encrypted with Customer-Supplied Encryption Key (CSEK)🟢1🟢 x6no data
🛡️ Google GCE Instance Confidential Compute is not enabled🟢1🟢 x6no data