4.2.2 PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies
PAN is secured with strong cryptography whenever it is sent via end-user messaging technologies.
5
artefacts
1
held by a system
0
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Evidence of detection or blocking in practice, such as data loss prevention rule output for PAN patterns in messaging · Document repository
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Documented policies and procedures prohibiting cleartext PAN over end-user messaging technologies such as email, chat and SMS · Policy repository / GRC workspace
- System configurations and vendor documentation showing the mechanism that secures or blocks PAN in those channels · Vendor register / contract repository
- The defined process for handling a customer or third party who sends PAN in the clear, including secure alternatives offered · Vendor register / contract repository
- Awareness material showing personnel know they must not transmit PAN this way · HR system / LMS
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Document repository on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Policy forbids the practice with no technical detection, so the only evidence is that nobody has reported it
- Email covered while chat, ticketing systems and SMS carry the same data unmonitored
- Inbound PAN from customers accepted and left sitting in mailboxes and ticket histories in the clear
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet4.2.1.2 Wireless networks transmitting PAN use strong cryptography · 5.1.1 All security policies and operational procedures that are identified in Requirement 5 are: • Documented. • Kept up to date. • In use. • Known to all affected parties