PCI Council’s High-Value Token Definition Disappointing
Written by Walter ConwayPCI Columnist Walter Conway thought a token was a token. Whether a particular token, or tokenization approach, was in or out of PCI scope seemed to depend on how well it was constructed and how the tokenization engine and token vault were implemented. But it seems that some tokens are more equal than others. For example, E-Commerce merchants who use tokens for one-click ordering and repeat purchases (leaving the underlying primary account numbers with their processor or another third party) just learned their tokens will still be in scope for PCI. Wonder if that hotel room keycard (or resort account) used to charge meals is a high-value token because it generates a payment-card transaction? How about the tokens used for exception-item-processing such as chargebacks and refunds. Are they high-value tokens because they impact (even if it is to reverse) transactions?
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Pages: 1 2
Leave a Reply
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
