The Payment Card Industry Data Security Standard (PCI DSS) has provided a common framework of technical and operational requirements for protecting cardholder account data. Companies that accept, process, or service credit card payments have to follow PCI DSS. Annual assessments for compliance are required, and non-compliance may result in penalty fines, increased transaction costs, and other consequences.
Wherever credit card numbers are stored—or extracted from a database and saved, even as as unstructured data in files on employee devices and file servers—they pose an obligation. With PKWARE’s automated file redaction technology, organizations can remediate sensitive data as soon as it arrives, and also remove credit card numbers from legacy data, taking petabytes of stored data out of PCI DSS scope. Download this solution overview to learn more.
Why Redaction Removes a File From PCI Scope
Tokenization and encryption are reversible by design, which is what makes them useful and also what keeps the data in scope. Redaction is not reversible. The card number is gone, the rest of the file is unchanged, and the file no longer holds cardholder data for an assessor to examine.
That is a scope decision rather than a security upgrade, and scope is what determines the cost of every annual assessment that follows.
Where Card Numbers Actually Accumulate
Cardholder data rarely stays in the system that was designed to hold it. It is extracted for a report, saved to a spreadsheet, attached to an email, and ends up as unstructured files on laptops, desktops and file servers.
Every one of those copies carries the same obligation as the database it came from, and none of them appears in the architecture diagram the assessment was scoped against.
How the Automated Workflow Runs
Scanning. File contents are searched at the element level for number sequences matching the algorithms published by the major card issuers, using machine learning and other heuristics to keep the scan efficient and the false positives low. It can run on a schedule, on demand, or in real time as files appear.
Copy and quarantine, optionally. Where the original values still have value for testing or analytics, a duplicate can be written to a quarantined location and protected with transparent or persistent encryption before the working copy is redacted.
Classification and redaction by policy. Persistent classification is applied to files, data and repositories as they are created, moved, shared, duplicated or saved. Card data is redacted so the original cannot be reconstructed; files not covered by PCI DSS are left untouched. Ready-made PCI DSS policies exist, and custom policies can be written.
Continuous monitoring. File activity on servers, desktops and laptops is watched, and every creation or modification triggers a scan. Scanning and remediation are recorded in immutable logs, which is what makes the control reportable rather than merely present.
Legacy Data Is the Larger Win
Stopping new exposure matters, but the volume is in what has already accumulated. Removing card numbers from historical files can take terabytes, in some estates petabytes, of stored data out of PCI DSS scope in a single pass.
What It Covers
Scanning and redaction run on Microsoft Windows, with a management console available as a hardware appliance, a virtual appliance or Windows Server software. Card number patterns cover Visa, MasterCard, American Express, Discover, Diners and JCB among others.
File coverage is deliberately broad, because card data does not respect format: DOC and DOCX, XLS and XLSX, PPT and PPTX, VSD and VSDX, XML and OOXML, PDF, TXT, CSV, MDB, ACCDB, MSG, RTF, LOG, JSON and ZIP.
