Answer yes if your organisation performs any activities or may otherwise impact the security of cardholder data or related sensitive authentication data related to payment processing. Cardholder data includes data such as the Primary Account Number, Cardholder Name, Expiration Date, and Service Code. Sensitive authentication data includes data such as full track data, card verification code, PINs, etc.
This question seeks to determine whether your organisation processes CHD data or may otherwise impact the security of CHD or SAD. It applies not only to those who directly handle or process CHD but also to those who provide services that could impact the security of that data. If so, you may be subject to compliance requirements under the Payment Card Industry Data Security Standard (PCI DSS).
You should map data flows to understand if payment-related data enters, moves through, or leaves your systems. Even if you may not directly handle or process CHD or SAD, you may be providing services (i.e. as a managed service provider) that could have an impact on the security of that data. You should answer “Yes” to this question if you have any data flows that meet these criteria.
If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.