Security Rules and Procedures 28 February 2017
Total Page:16
File Type:pdf, Size:1020Kb
Security Rules and Procedures 28 February 2017 SP Summary of Changes, 28 February 2017 Summary of Changes, 28 February 2017 This manual reflects changes associated with announcements in Mastercard bulletins from 1 August 2016 to 1 February 2017, and additional terminology changes. Please click the hyperlinked section numbers to locate the changes listed below. Description of Change Where to Look Added definitions of the following terms: Global Collection Only (GCO) Data Definitions Collection Program; Payment Account Reference (PAR). Clarified the requirements for a PAN of a Mastercard Account. 3.2 Clarified the description of the Issuer-assigned portion of a Maestro Account 3.3 PAN or Cirrus Account PAN. Added cross-references to the International Electrotechnical Commission • 3.3 (IEC) to applicable cross-references to the International Organization for • 3.5 Standardization (ISO). • 3.5.4 • 3.11 • 4.2 • 4.10 Added titles to ISO/IEC Standard cross-references. • 3.3 • 3.10.5 • 4.2 • 4.10 • 6.3.3.3 Clarified the signature panel requirements for a Card. 3.4 Updated titles of ISO/IEC Standard cross-references. 3.5 Clarified the definition of a magnetic stripe-read counterfeit Transaction to 6.3.2.2 align with the definitions of a key-entered counterfeit Transaction and an imprinted counterfeit Transaction. Added tobacco product Merchants that conduct non-face-to-face 9.4.3 Transactions of any electronic nicotine delivery system to the types of non- face-to-face tobacco product Merchants required to be registered using the MRP. Added Poland to the countries under MCC 9406 in which government- • 9.4.4 owned lottery Merchants must be registered using the MRP. • 9.4.4.2 ©1991–2017 Mastercard. Proprietary. All rights reserved. Security Rules and Procedures • 28 February 2017 2 Contents Contents Summary of Changes, 28 February 2017......................................................... 2 Chapter 1: Customer Obligations...................................................................... 11 1.1 Compliance with the Standards..................................................................................12 1.2 Conflict with Law.......................................................................................................12 1.3 The Security Contact.................................................................................................. 12 Chapter 2: Card Production Standards............................................................13 2.1 Compliance with Card Production Standards..............................................................14 2.2 Monitoring of Personnel.............................................................................................14 2.3 Contracting with Card Registration Companies.......................................................... 15 2.4 Working with Vendors............................................................................................... 16 2.4.1 Order Request Required to Produce Cards...........................................................17 2.4.2 Stockpiling Plastics..............................................................................................17 2.5 Cards Without Personalization................................................................................... 17 2.6 Card Count Discrepancies.......................................................................................... 17 2.7 Reporting Card Loss or Theft......................................................................................17 2.8 Disposition of Unissued Cards and Account Information.............................................18 Chapter 3: Card and Access Device Design Standards............................ 19 3.1 Principles of Standardization...................................................................................... 21 3.2 Mastercard Account Number......................................................................................21 3.3 Maestro and Cirrus Account Numbers........................................................................22 3.4 Signature Panel.......................................................................................................... 22 3.5 Magnetic Stripe or Mastercard HoloMag Encoding..................................................... 22 3.5.1 Card Validation Code 1 (CVC 1)......................................................................... 23 3.5.2 Service Code...................................................................................................... 23 3.5.3 Cardholder Name............................................................................................... 23 3.5.4 Expiration Date...................................................................................................24 3.6 Chip Cards.................................................................................................................25 3.6.1 Chip Card Applications.......................................................................................26 3.6.1.1 Compliance Assessment and Security Testing.............................................. 26 3.6.1.2 Integrated Circuit Chip Providers................................................................. 27 3.6.2 Multiple Application Chip Cards......................................................................... 27 3.6.3 Use of M/Chip Card Application Specifications....................................................27 3.7 Contactless Cards and Payment Devices..................................................................... 27 3.8 Mobile Payment Devices.............................................................................................28 3.9 Consumer Device Cardholder Verification Methods.................................................... 29 ©1991–2017 Mastercard. Proprietary. All rights reserved. Security Rules and Procedures • 28 February 2017 3 Contents 3.9.1 Mastercard Qualification of Consumer Device CVMs...........................................29 3.9.2 CDCVM Functionality......................................................................................... 30 3.9.3 Persistent Authentication....................................................................................30 3.9.4 Prolonged Authentication...................................................................................31 3.9.5 Maintaining Mastercard-qualified CVM Status.................................................... 31 3.9.6 Issuer Responsibilities..........................................................................................31 3.9.7 Use of a Vendor..................................................................................................32 3.10 Card Validation Code (CVC)..................................................................................... 32 3.10.1 Issuer Requirements for CVC 1......................................................................... 33 3.10.2 Issuer Requirements for CVC 2......................................................................... 33 3.10.3 Issuer Requirements for CVC 3......................................................................... 34 3.10.4 Acquirer Requirements for CVC 2..................................................................... 34 3.10.5 CVC Calculation Methods................................................................................ 34 3.11 Service Codes...........................................................................................................36 3.11.1 Issuer Information.............................................................................................36 3.11.2 Acquirer Information........................................................................................ 37 3.11.3 Valid Service Codes...........................................................................................37 3.11.4 Additional Service Code Information.................................................................38 Chapter 4: Terminal and PIN Security Standards....................................... 40 4.1 Personal Identification Numbers (PINs)........................................................................41 4.2 PIN Selection and Usage.............................................................................................41 4.3 PIN Verification...........................................................................................................42 4.4 PIN Authorization Requests........................................................................................ 42 4.5 PIN Encipherment.......................................................................................................42 4.6 PIN Key Management.................................................................................................43 4.6.1 PIN Transmission Between Customer Host Systems and the Interchange System........................................................................................................................ 43 4.6.2 On-behalf Key Management...............................................................................44 4.7 PIN at the Point of Interaction (POI) for Mastercard Magnetic Stripe Transactions........45 4.8 Terminal Security Standards........................................................................................45 4.9 Hybrid Terminal Security Standards.............................................................................46 4.10 PIN Entry Device Standards.......................................................................................46