October 5, 2017
The Accredited Standards Committee X9 Inc., a nonprofit accredited by the American National Standards Institute to develop domestic and international standards for the financial services industry, has publishedX9.119 Protection of Sensitive Payment Card Data – Part 2: Implementing Post-Authorization Tokenization Systems.
The new ANSI standard defines the minimum security requirements for implementing tokenization in systems that operate after a payment has been approved, a press release said.
Tokenization is the use of a data element called a token that has no intrinsic value or meaning, as a substitute for a sensitive data element such as a credit card number or other customer data.
Increasingly, payment card transactions use tokens to prevent disclosure of sensitive data during data breaches; standards for tokenization ensure uniform procedures and true security, the release said
The new standard was developed by the cryptographic protocol and application security working group of the X9F data and information security subcommittee.
X9.119-2 is available from the X9 Standards Store.