{"id":3786,"date":"2024-11-12T15:47:56","date_gmt":"2024-11-12T14:47:56","guid":{"rendered":"https:\/\/pcihispano.com\/?p=3786"},"modified":"2026-05-06T19:15:05","modified_gmt":"2026-05-06T17:15:05","slug":"datos-dentro-y-fuera-del-alcance-de-pci-dss","status":"publish","type":"post","link":"https:\/\/www.pcihispano.com\/en\/datos-dentro-y-fuera-del-alcance-de-pci-dss\/","title":{"rendered":"Data inside and outside the scope of PCI DSS"},"content":{"rendered":"<p><span class=\"intro-text\">One of the critical tasks in PCI DSS compliance is scope identification (<em>scope<\/em>) compliance. The first step in determining which assets are within or outside that scope is the identification of the <strong>type of data<\/strong> of payment cards that are processed, stored and\/or transmitted by the entity and the <strong>format<\/strong> of such data. Depending on this, the entity may determine the associated infrastructure (servers, applications, NSCs, databases, wireless networks, virtualization systems, etc.), locations, personnel, and third parties that will be part of its compliance environment.<\/span><\/p>\n<p>The PCI DSS standard applies to all entities that store, process or transmit cardholder data (<em>Cardholder Data<\/em> \u2013 CHD) and\/or sensitive authentication data (<em>Sensitive Authentication Data<\/em> \u2013 SAD) \u2013 jointly referred to as \u2018account data\u2019 (<em>Account Data<\/em>) \u2013 or that could affect the security of cardholder data and\/or sensitive authentication data.<\/p>\n<div id=\"attachment_3787\" style=\"width: 1196px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3787\" class=\"size-full wp-image-3787\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2024\/07\/Account_Data.png?resize=900%2C210&#038;ssl=1\" alt=\"\" width=\"900\" height=\"210\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Account_Data.png?w=1186&amp;ssl=1 1186w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Account_Data.png?resize=300%2C70&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Account_Data.png?resize=1024%2C239&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Account_Data.png?resize=768%2C179&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Account_Data.png?resize=500%2C117&amp;ssl=1 500w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><p id=\"caption-attachment-3787\" class=\"wp-caption-text\">Account Data in PCI DSS<\/p><\/div>\n<p>Likewise, the PCI DSS standard establishes the controls that must be applied during the storage of this data, taking into account that if the PAN is stored together with other elements of the holder's data (CHD), then only the PAN must be unreadable.<\/p>\n<div id=\"attachment_3789\" style=\"width: 951px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3789\" class=\"wp-image-3789\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2024\/07\/Data_storage_PCIDSS.png?resize=900%2C315&#038;ssl=1\" alt=\"\" width=\"900\" height=\"315\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Data_storage_PCIDSS.png?w=1513&amp;ssl=1 1513w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Data_storage_PCIDSS.png?resize=300%2C105&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Data_storage_PCIDSS.png?resize=1024%2C358&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Data_storage_PCIDSS.png?resize=768%2C269&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/Data_storage_PCIDSS.png?resize=500%2C175&amp;ssl=1 500w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><p id=\"caption-attachment-3789\" class=\"wp-caption-text\">Controls for card data storage<\/p><\/div>\n<p>However, <span class=\"highlight\">depending on what type of security controls are applied to the data and the format used, the scope (<em>scope<\/em>) compliance can be extended or minimized.<\/span> That is why it is imperative to understand how applicability criteria are established based on data types and their data formats BEFORE proceeding with scope identification (req. 12.5.2 of PCI DSS v4.x):<\/p>\n<div id=\"attachment_3790\" style=\"width: 801px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3790\" class=\"wp-image-3790\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2024\/07\/12.5.2.png?resize=791%2C535&#038;ssl=1\" alt=\"\" width=\"791\" height=\"535\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/12.5.2.png?w=1002&amp;ssl=1 1002w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/12.5.2.png?resize=300%2C203&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/12.5.2.png?resize=768%2C520&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/07\/12.5.2.png?resize=500%2C338&amp;ssl=1 500w\" sizes=\"auto, (max-width: 791px) 100vw, 791px\" \/><p id=\"caption-attachment-3790\" class=\"wp-caption-text\">PCI DSS requirement 12.5.2 related to scope of compliance documentation<\/p><\/div>\n<p>Listed below are the types of data and other related assets that may or may not be in scope depending on their format and functionality. However, it is clarified that the applicability of these criteria may vary depending on the responsibilities and access permissions of the entities and\/or systems involved:<\/p>\n<table style=\"height: 246px;\" width=\"1247\">\n<tbody>\n<tr>\n<th>Data type<\/th>\n<th>When are they <span style=\"color: #ff0000;\">INSIDE<\/span> of scope?<\/th>\n<th>When are they <span style=\"color: #00ff00;\">OUTSIDE<\/span> of scope?<\/th>\n<th>References<\/th>\n<\/tr>\n<tr class=\"odd\">\n<td><span style=\"color: #000000;\"><strong>Account data (CHD and SAD) in clear text<\/strong><\/span><\/td>\n<td>Clear text card data can be temporarily stored in non-persistent memory (RAM memory, for example) while being processed. However, the systems that process this data will be within reach.<\/td>\n<td>N\/A<\/td>\n<td>FAQ #1042: <a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/should-cardholder-data-be-encrypted-while-in-memory\/\" target=\"_blank\" rel=\"noopener\"><em>Should cardholder data be encrypted while in memory?<\/em><\/a><\/td>\n<\/tr>\n<tr class=\"even\">\n<td><span style=\"color: #000000;\"><strong>Encrypted NAP data<\/strong><\/span><\/td>\n<td>Encrypted PAN data will remain within the scope of PCI DSS:<\/p>\n<ul>\n<li>If the encrypted data has not been isolated from encryption and decryption processes and key management functions.<\/li>\n<li>Whether the encrypted data is present on a system or medium that also contains the decryption key.<\/li>\n<li>Whether the encrypted data is present in the same environment in which the decryption key is located.<\/li>\n<li>Whether the encrypted data is accessible to an entity that also has access to the decryption key.<\/li>\n<\/ul>\n<p>Similarly, systems that execute encryption and data decryption routines, systems that perform key management tasks, and any connected system or network should be within reach.<\/td>\n<td>Encrypted PAN data can be considered out of reach when the entity receives and\/or stores encrypted data only, does not have access to clear data or related cryptographic keys, nor does it have the ability to decrypt them.<\/td>\n<td>Section 4 of the PCI DSS standard: <em>Scope of PCI DSS Requirements<\/em><\/p>\n<p>FAQ #1086: <em><a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/how-does-encrypted-cardholder-data-impact-pci-dss-scope\/\" target=\"_blank\" rel=\"noopener\">How does encrypted cardholder data impact PCI DSS scope?<\/a><\/em><\/td>\n<\/tr>\n<tr class=\"odd\">\n<td><span style=\"color: #000000;\"><strong><em>Hash<\/em> cryptographic with key (<em>keyed cryptographic hashing<\/em>)<\/strong><\/span><\/td>\n<td>Full PAN data protected with <em>hash<\/em> Keyed cryptographic will be in range if this data is stored on the same system that runs the <em>hashing<\/em>.<\/p>\n<p>Similarly, systems that run routines of <em>hashing<\/em> data, systems performing key management tasks and any connected system or network shall be within range.<\/td>\n<td>PAN data protected with <strong><em>hash<\/em> cryptographic with key<\/strong> may be considered out of reach where such data:<\/p>\n<ul>\n<li>They are transferred and stored in a separate environment (adequately segmented from the CDE).<\/li>\n<li>You do not have access to the original clear PAN or associated cryptographic keys.<\/li>\n<li>Cardholder data (CHD) or sensitive authentication data (SAD) are not otherwise processed, stored and\/or transmitted.<\/li>\n<\/ul>\n<\/td>\n<td>FAQ #1089: <a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/how-can-hashing-be-used-to-protect-primary-account-numbers-pan-and-in-what-circumstances-can-hashed-pans-be-considered-out-of-scope-for-pci-dss\/\" target=\"_blank\" rel=\"noopener\"><em>How can hashing be used to protect Primary Account Numbers (PAN) and in what circumstances can hashed PANs be considered out of scope for PCI DSS?<\/em><\/a><\/td>\n<\/tr>\n<tr class=\"even\">\n<td><strong>Tokenized PAN data (acquisition tokens)<br \/>\n<\/strong><\/td>\n<td>When purchasing tokens are used, different methods can be used for their generation.<\/p>\n<p>However, PAN tokens will be in range if they are stored on the same system that runs the tokenization.<\/p>\n<p>Similarly, systems that run data tokenization routines, systems that perform key management tasks (if applicable), and any connected systems or networks should be within reach.<\/td>\n<td>PAN data protected by <strong>tokenization<\/strong> may be considered out of reach where such data:<\/p>\n<ul>\n<li>They are transferred and stored in a separate environment (adequately segmented from the CDE).<\/li>\n<li>You do not have access to the original clear PAN or associated cryptographic keys.<\/li>\n<li>Cardholder data (CHD) or sensitive authentication data (SAD) are not otherwise processed, stored and\/or transmitted.<\/li>\n<\/ul>\n<\/td>\n<td>FAQ #1384: <a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/what-is-the-difference-between-acquiring-tokens-issuer-tokens-and-payment-tokens\/\" target=\"_blank\" rel=\"noopener\"><em>What is the difference between \u2018acquiring tokens\u2019, \u2018issuer tokens\u2019, and \u2018Payment Tokens\u2019?<\/em><\/a><\/p>\n<p>FAQ #1385: <a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/which-types-of-tokens-are-addressed-by-the-pci-ssc-tokenization-documents\/\" target=\"_blank\" rel=\"noopener\"><em>Which types of tokens are addressed by the PCI SSC tokenization documents?<\/em><\/a><\/td>\n<\/tr>\n<tr class=\"odd\">\n<td><strong>Truncated PAN data (<em>truncated<\/em>)<\/strong><\/td>\n<td>When truncation of the NAP (removal of a certain number of digits) is used for storage following <a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/What-are-acceptable-formats-for-truncation-of-primary-account-numbers\/\" target=\"_blank\" rel=\"noopener\">the criteria laid down by the trade marks<\/a>, the systems executing the truncation as well as any connected system or network shall be within range.<\/td>\n<td>PAN data protected by <strong>truncation<\/strong> during storage may be considered out of reach where such data:<\/p>\n<ul>\n<li>They are transferred and stored in a separate environment (adequately segmented from the CDE).<\/li>\n<li>You do not have access to the original PAN in clear.<\/li>\n<li>Cardholder data (CHD) or sensitive authentication data (SAD) are not otherwise processed, stored and\/or transmitted.<\/li>\n<\/ul>\n<\/td>\n<td>FAQ #1117: <em><a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/are-truncated-primary-account-numbers-pan-required-to-be-protected-in-accordance-with-pci-dss\/\" target=\"_blank\" rel=\"noopener\">Are truncated Primary Account Numbers (PAN) required to be protected in accordance with PCI DSS?<\/a><\/em><\/p>\n<p>FAQ #1091: <em><a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/What-are-acceptable-formats-for-truncation-of-primary-account-numbers\" target=\"_blank\" rel=\"noopener\">What are acceptable approved for truncation of primary account numbers?<\/a><\/em><\/p>\n<p>FAQ #1315: <em><a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/is-storage-of-truncated-pan-considered-storage-of-cardholder-data-per-the-saq-eligibility-criteria\/\" target=\"_blank\" rel=\"noopener\">Is storage of truncated PAN considered storage of \"cardholder data\" per the SAQ eligibility criteria?<\/a><\/em><\/td>\n<\/tr>\n<tr class=\"even\">\n<td><strong>Masked PAN data (<em>masked<\/em>)<\/strong><\/td>\n<td>When masking is used (<em>masking<\/em>) in order to protect the NAP during its display on screens, receipts, printouts, etc., the systems performing the masking, as well as any connected system or network, shall be within range.<\/td>\n<td>PAN data protected with <strong>masking<\/strong> during display they can be considered out of reach when the display of the original PAN is not allowed in any way (e.g. on paper receipts).<\/td>\n<td>FAQ #1146: <em><a href=\"https:\/\/www.pcisecuritystandards.org\/faq\/articles\/Frequently_Asked_Question\/What-is-the-difference-between-masking-and-truncation\/\" target=\"_blank\" rel=\"noopener\">What is the difference between masking and truncation?<\/a><\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Once the entity has made the identification of its scope, it is recommended to involve a <a href=\"https:\/\/listings.pcisecuritystandards.org\/assessors_and_solutions\/qualified_security_assessors\" target=\"_blank\" rel=\"noopener\">QSA Advisor<\/a> for evaluation.<\/p>\n<p>Leave us a message if you have any questions about this article.<\/p>","protected":false},"excerpt":{"rendered":"<p>One of the critical tasks in PCI DSS compliance is the identification of scope of compliance. The first step in determining which assets are in or out of that range is identifying the type of data [\u2026]<\/p>","protected":false},"author":2,"featured_media":4995,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1,354],"tags":[151,17,229,19,226,150,227,20,228],"class_list":["post-3786","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contenido","category-pcidss","tag-alcance","tag-cifrado","tag-enmascarado","tag-hash","tag-in-out","tag-scope","tag-texto-claro","tag-tokenizacion","tag-truncado"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/08\/data_in_out_pci_scope.png?fit=1273%2C712&ssl=1","jetpack-related-posts":[{"id":243,"url":"https:\/\/www.pcihispano.com\/en\/que-es-pci-dss\/","url_meta":{"origin":3786,"position":0},"title":"\u00bfQu\u00e9 es PCI DSS?","author":"David Acosta","date":"agosto 18, 2024","format":false,"excerpt":"En esta nueva serie de art\u00edculos de PCI Hispano se presentar\u00e1 una descripci\u00f3n general de cada uno de los est\u00e1ndares publicados actualmente por el Consejo de Est\u00e1ndares de Seguridad de la Industria de Tarjetas de Pago (Payment Card Industry Security Standards Council \u2013 PCI SSC) para la protecci\u00f3n de los\u2026","rel":"","context":"In &quot;Destacado&quot;","block_context":{"text":"Destacado","link":"https:\/\/www.pcihispano.com\/en\/category\/destacado\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":7124,"url":"https:\/\/www.pcihispano.com\/en\/vcc-virtual-credit-cards-y-pci-dss\/","url_meta":{"origin":3786,"position":1},"title":"VCC (Virtual Credit Cards) y PCI DSS","author":"David Acosta","date":"septiembre 18, 2025","format":false,"excerpt":"Probablemente una de las dudas m\u00e1s recurrentes durante la identificaci\u00f3n del alcance (scope) de PCI DSS de una entidad que usa Virtual Credit Cards (VCCs) es si este tipo de tarjetas est\u00e1n o no en el alcance. Pero, \u00bfqu\u00e9 son las tarjetas VCC y por qu\u00e9 su uso (a pesar\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/08\/VCC-back.png?fit=1200%2C676&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/08\/VCC-back.png?fit=1200%2C676&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/08\/VCC-back.png?fit=1200%2C676&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/08\/VCC-back.png?fit=1200%2C676&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/08\/VCC-back.png?fit=1200%2C676&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":4508,"url":"https:\/\/www.pcihispano.com\/en\/cinco-puntos-clave-del-nuevo-documento-para-la-definicion-de-alcance-y-segmentacion-en-arquitecturas-de-red-modernas\/","url_meta":{"origin":3786,"position":2},"title":"5 puntos clave del documento para la definici\u00f3n de alcance y segmentaci\u00f3n en arquitecturas de red modernas","author":"David Acosta","date":"septiembre 19, 2024","format":false,"excerpt":"En septiembre de 2025 el PCI SSC public\u00f3 un nuevo suplemento informativo para la definici\u00f3n del alcance y segmentaci\u00f3n en arquitecturas de red modernas (Information Supplement - PCI DSS Scoping and Segmentation Guidance for Modern Network Architectures). En este art\u00edculo analizamos los cinco puntos clave de ese nuevo documento y\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":1732,"url":"https:\/\/www.pcihispano.com\/en\/aws-publica-su-guia-de-cumplimiento-con-pci-dss-v4-0\/","url_meta":{"origin":3786,"position":3},"title":"AWS publica su gu\u00eda de cumplimiento con PCI DSS v4.0","author":"David Acosta","date":"noviembre 28, 2023","format":false,"excerpt":"Como parte de sus esfuerzos para facilitar la implementaci\u00f3n de los controles de diferentes est\u00e1ndares de seguridad en los entornos de sus clientes, Amazon Web Services (AWS), como proveedor de servicios en la nube (Cloud Service Provider - CSP), public\u00f3 en agosto de 2023 la actualizaci\u00f3n de su Gu\u00eda de\u2026","rel":"","context":"In &quot;Noticias&quot;","block_context":{"text":"Noticias","link":"https:\/\/www.pcihispano.com\/en\/category\/noticias\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/aws_pcidss.png?fit=1200%2C676&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/aws_pcidss.png?fit=1200%2C676&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/aws_pcidss.png?fit=1200%2C676&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/aws_pcidss.png?fit=1200%2C676&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/aws_pcidss.png?fit=1200%2C676&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":9488,"url":"https:\/\/www.pcihispano.com\/en\/guia-para-entender-los-tipos-de-tokens-y-su-uso\/","url_meta":{"origin":3786,"position":4},"title":"Gu\u00eda para entender los tipos de tokens y su uso","author":"David Acosta","date":"noviembre 20, 2025","format":false,"excerpt":"Uno de los controles clave del est\u00e1ndar PCI DSS v4.0 es el requerimiento 3.5. En \u00e9l se enumeran una serie de t\u00e9cnicas para la protecci\u00f3n del PAN (Primary Account Number) cuando este debe almacenarse,\u00a0si existe alguna justificaci\u00f3n de negocio.\u00a0 Los m\u00e9todos que pueden emplearse para dicha protecci\u00f3n son el uso\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/10\/token.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/10\/token.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/10\/token.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/10\/token.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/10\/token.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":477,"url":"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-vii-requerimiento-12\/","url_meta":{"origin":3786,"position":5},"title":"An\u00e1lisis de PCI DSS v4.0 \u2013 Parte VII: Requerimiento 12","author":"David Acosta","date":"noviembre 17, 2022","format":false,"excerpt":"En este pen\u00faltimo art\u00edculo de la serie \u201cAn\u00e1lisis de PCI DSS v4.0\u201d se presenta un an\u00e1lisis a los cambios del requerimiento 12 - parte del grupo 6 \u201cMaintain an Information Security Policy\u201d- en la versi\u00f3n 4.0 del est\u00e1ndar PCI DSS. Requerimiento 12: Support Information Security with Organizational Policies and Programs\u2026","rel":"","context":"In &quot;An\u00e1lisis de PCI DSS v4.0&quot;","block_context":{"text":"An\u00e1lisis de PCI DSS v4.0","link":"https:\/\/www.pcihispano.com\/en\/category\/pci-dss-4-0\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/3786","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/comments?post=3786"}],"version-history":[{"count":1,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/3786\/revisions"}],"predecessor-version":[{"id":11724,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/3786\/revisions\/11724"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media\/4995"}],"wp:attachment":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media?parent=3786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/categories?post=3786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/tags?post=3786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}