PA-DSSThe Payment Application Data Security Standard (PA-DSS) is for software developers and integrators of
payment applications that store, process or transmit cardholder data as part of authorization or settlement
when these applications are sold, distributed or licensed to third parties.
Most card brands encourage
merchants and third party agents to use payment applications that are validated independently by a PA-QSA
company and accepted for listing by the PCI SSC.
PA-DSS Requirements
- Do not retain full magnetic stripe, card validation, code or value, or PIN block data
- Protect stored cardholder data
- Provide secure authentication features
- Log payment application activity
- Develop secure payment applications
- Protect wireless transmissions
- Test payment applications to address vulnerabilities
- Facilitate secure network implementation
- Cardholder data must never be stored on a server connected to the internet
- Facilitate secure remote software updates
- Facilitate secure remote access to payment application
- Encrypt sensitive traffic over public networks
- Encrypt all non-console administrative access
- Maintain instructional documentation and training programs for customers, resellers, and integrators
Usage: "An ecommerce site must meet the specifications
of the PCI SSC in order to be considered PA-DSS compliant."
Related terms:
|
 |
Return to the Ecommerce Glossary
|