Talk:Payment Card Industry Data Security Standard
Add topicAppearance
Latest comment: 5 months ago by ~2026-21336-26 in topic Proposed section: Telephone and call centre compliance
| This article is rated C-class on Wikipedia's content assessment scale. It is of interest to the following WikiProjects: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Archives (Index) |
|
This page is archived by ClueBot III. |
| The Certified Payment-Card Industry Security Implementer article was blanked on 25 August 2026 and that title now redirects to Payment Card Industry Data Security Standard. The contents of the former article are available in the redirect's history. |
| The Certified Payment-Card Industry Security Auditor article was blanked on 25 August 2026 and that title now redirects to Payment Card Industry Data Security Standard. The contents of the former article are available in the redirect's history. |
| The Certified Payment-Card Industry Security Manager article was blanked on 25 August 2026 and that title now redirects to Payment Card Industry Data Security Standard. The contents of the former article are available in the redirect's history. |
Wiki Education assignment: Social Informatics - ITI 547-200 Section 07
[edit]
This article was the subject of a Wiki Education Foundation–supported course assignment, between 4 September 2025 and 10 December 2025. Further details are available on the course page. Student editor(s): Leaves.of.Three (article contribs).
— Assignment last updated by NicholasJohnstoneNMJ83 (talk) 22:47, 22 October 2025 (UTC)
Proposed section: Telephone and call centre compliance
[edit]Hello,
I noticed that the French Wikipedia article on PCI DSS ([[:fr:Norme de sécurité de l'industrie des cartes de paiement|fr:Norme de sécurité de l'industrie des cartes de paiement]], section 7.2) covers call centre security and DTMF masking as a compliance topic, but the English article has no equivalent section.
Telephone-based card payments are a significant area of PCI DSS compliance — the PCI Security Standards Council has published specific guidance on protecting telephone-based payment card data, and DTMF masking technology is widely deployed across contact centre environments.
I'd like to propose adding a subsection on telephone and call centre compliance,
covering:
* PCI SSC guidance on call recordings containing cardholder data
* Technical approaches to scope reduction (IVR, DTMF masking, pause-and-resume)
* How channel separation and DTMF suppression affect self-assessment scope
=== Proposed draft text ===
Organisations that accept payment card data over the telephone face specific PCI DSS
compliance challenges, as call recordings, agent workstations, and telephony
infrastructure may all come into contact with cardholder data. The PCI Security
Standards Council has issued guidance noting that digital call recordings containing
sensitive authentication data must not be stored after authorisation, regardless of
encryption method used.
Several technical approaches have been developed to reduce PCI DSS scope in telephone
payment environments:
* Interactive voice response (IVR): Calls are transferred to an automated
system for card data entry, removing agents from the payment flow entirely. This
approach eliminates agent exposure to cardholder data but interrupts the
customer–agent interaction.
* DTMF masking: Customers enter card details using their telephone keypad while remaining on the call with an agent. The dual-tone multi-frequency (DTMF) signals are intercepted and replaced with flat tones in real time, preventing the agent or call recording systems from capturing the card data. The payment data is routed directly to a payment processor through a separate channel.
* Pause and resume: Call recording is manually or automatically paused while
the customer provides card details, then resumed. This reduces recording exposure but
does not prevent agent access to spoken card data.
The use of DTMF masking and channel separation technologies can allow organisations
to reduce their PCI DSS self-assessment scope, as cardholder data does not enter the
merchant's environment.
=== References ===
All statements can be sourced from PCI Security Standards Council publications
including the Information Supplement on Protecting Telephone-Based Payment Card Data
and PCI DSS v4.0 Requirement 3.
Disclosure: I work for a company that operates in the telephone payment
security space. I am proposing this content for editorial review rather than adding
it directly, per WP:COI guidelines. Curtlondon (talk) 13:47, 6 April 2026 (UTC)
- @Curtlondon: We are highly unlikely to add text that has come directly from an AI chatbot. Sorry. • a frantic turtle 🐢 14:12, 6 April 2026 (UTC)
- Oh dear, I did not realise there was a ban on AI content even if it factually correct and helps someone. ~2026-21336-26 (talk) 10:35, 7 April 2026 (UTC)
Categories:
- C-Class Computer security articles
- High-importance Computer security articles
- C-Class Computer security articles of High-importance
- C-Class Computing articles
- High-importance Computing articles
- All Computing articles
- All Computer security articles
- C-Class Finance & Investment articles
- High-importance Finance & Investment articles
- WikiProject Finance & Investment articles
- C-Class WikiProject Business articles
- Mid-importance WikiProject Business articles
- WikiProject Business articles
- C-Class Cryptography articles
- Mid-importance Cryptography articles
- C-Class Computer science articles
- Mid-importance Computer science articles
- WikiProject Computer science articles
- WikiProject Cryptography articles
- C-Class Internet articles
- Mid-importance Internet articles
- WikiProject Internet articles
- C-Class law articles
- Low-importance law articles
- WikiProject Law articles

