NetKey
 
 
  News & Features   Become a Member   Member Directory
    

 

 
 
Use this quick form to send a request for information to our members!
Category
ADA Advertising Associations & Organizations ATMs Audio Barcode Readers Bill Payment/ Money Transfer C-stores Cables Card Readers/Writers Cash Acceptors & Dispensers Cell Phone Top-up, Payment Check Readers (MICR) Coin Counting Kiosk Communication - Networking, Wireless Computers - Desktop, Laptop, Industrial, Thin, Panel, Embedded Connectivity Consulting Contactless Payments Cooling Systems Coupon CRM Debit/Credit/Smart Cards Design Digital Downloads - Music, Ring Tones, Movies Digital Signage DVD Kiosk Enclosures Entertainment & Gaming Equipment Leasing and Rental Exhibits & Displays Financial Gift Registry Government Graphic Production Hardware Healthcare Human Resources & Recruiting Industrial Input Devices - Trackballs, Joysticks, TouchPads, Stylus Installation Insurance Integration Internet Access/Pay for Use Inventory Extension Keyboards/Keypads Logistics, Deployment, Delivery Loyalty Maintenance & Service Management Systems Memory Readers (Flash & others) Mini Kiosks Mobile Monitoring Monitors Movie Rental MP3 & MP4 downloads Narrow Casting Outdoor Kiosks Paper Supplies Parking Parts Photo Kiosks Point of Sale Power Supply Prepaid calling cards Printers Product Information/ Ordering Product Information/Look-up Programmers & Application Developers Publications Remote Monitoring & Mgt. Restaurant/ Food Service Retail RFID Satellite Services Scanners Security & Biometric Identification Self Check-out/ Check-in Software - Linux/UNIX, middleware, Mac, OS, Multimedia Speakers Supply Surge Protection Survey Telephone Handsets Telephones/ Telephony Ticketing Total Solutions Turn-key Provider Touch Screen Monitors Touch Screens Trade Shows Transaction Processing Travel & Hospitality Vending Video - Players, Cards, etc. Watchdog/ Reboot Devices Wayfinding Wireless Devices
My Question:
Please enter the
verification code
displayed below. *
This field is case-sensitive.
We'll rush your request to our members!
 

 
News

    

PCI Security Standards Council expands PED program to include two devices

30 Jun 2008

WAKEFIELD, Mass. — The PCI Security Standards Council, a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (DSS), PCI PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS), has announced the addition of two new payment industry device types to the PED program to strengthen cardholder data security.
 
Unattended payment terminals and hardware (also known as host) security modules now can undergo a rigorous testing and approval program to ensure they comply with industry standards for securing sensitive payment card data during any point in the transaction process. The Council also will maintain the list of approved UPTs and HSMs, provide documentation and training for labs evaluating these devices and be a single source of information for device vendors and their customers.
 
The PED Security Requirements are designed to ensure the security of PIN-based transactions globally and apply to devices that accept PIN entry. Until now, the requirements focused on traditional point-of-sale devices that operate in an environment that is attended by a merchant, cashier or sales clerk. UPTs are unattended payment devices that include self-service ticketing machines, kiosks, automated fuel pumps and vending machines. Vendors have been manufacturing and having the encrypting PIN pads (EPPs) that go into UPTs evaluated by approved labs, and the payment card brands have been requiring the use of PCI SSC approved EPPs. Having new and overarching UPT testing requirements will further protect the payment card industry participants.
 
HSMs are secure cryptographic devices that can be used for PIN translation, card personalization, electronic commerce or data protection and do not include any type of cardholder interface. The addition of UPTs and HSMs into the PCI SSC security testing requirements enables the Council to provide testing laboratories with a streamlined evaluation process for achieving compliance of these cryptographic devices.
 
"PIN entry devices go well beyond the typical POS terminals we are all familiar with and we are continually expanding into more and more areas," said Bob Russo, general manager of the PCI Security Standards Council. "Any device that processes personal identification numbers is an important link in the transaction chain. By including both UPTs and HSMs in the PED Security Requirements, the Council is reaffirming its commitment to developing additional standards to meet the needs of the industry and to ensure continued safety and security for consumers."

©2008 NetWorld Alliance LLC. All rights reserved.

Need more info? Submit a Request for Information (RFI) to our members & get expert advice.
Give us details of what you're searching for:
We'll fire your request to our members ASAP!
Wincor Nixdorf ProConsult
 
Get the latest self-service & kiosk news delivered to your in-box. Click here to sign up for free.
 
Become a Member of the Self-Service