PCI SPoC

E723415

PCI SPoC is a PCI Security Standards Council standard that defines security requirements for accepting PIN-based card payments on commercial off-the-shelf mobile devices using a secure PIN entry application and a trusted card reader.

All labels observed (1)

Label Occurrences
PCI SPoC canonical 2

How this entity was disambiguated

Statements (46)

Predicate Object
instanceOf PCI SSC standard ⓘ
payment card security standard ⓘ
acronymFor Software-based PIN Entry on COTS ⓘ
addresses threats to PIN entry on mobile devices ⓘ
aimsTo reduce risk of PIN compromise on consumer-grade devices ⓘ
appliesTo commercial off-the-shelf mobile devices ⓘ
category cardholder data and PIN protection standard ⓘ
complianceDemonstratedBy assessment by PCI-recognized laboratories ⓘ
complianceListedOn PCI SSC list of approved SPoC solutions ⓘ
defines security requirements for accepting PIN-based card payments on COTS devices ⓘ
documentationType technical security standard ⓘ
focusesOn PIN-based cardholder verification ⓘ
software-based PIN entry ⓘ
fullName PCI Software-based PIN Entry on COTS ⓘ
goal enable secure PIN acceptance without traditional hardware PIN pads ⓘ
governs design of software-based PIN entry solutions ⓘ
integration between mobile apps and external card readers ⓘ
includesRequirementsFor application security ⓘ
device security controls ⓘ
key management and cryptography ⓘ
monitoring and integrity checks ⓘ
secure communication between PIN entry app and card reader ⓘ
industry payments industry ⓘ
intendedFor merchants using mobile devices for card-present PIN entry ⓘ
solution vendors building PIN-on-mobile products ⓘ
objective maintain security of PIN-based transactions ⓘ
protect PIN entry on COTS devices ⓘ
partOf PCI PIN security standards ecosystem ⓘ
publishedBy PCI Security Standards Council ⓘ
publisherAbbreviation PCI SSC ⓘ
regulates how PIN is captured, processed, and transmitted on COTS devices ⓘ
relatedTo PCI CPoC ⓘ
PCI MPoC ⓘ
PCI PTS POI ⓘ
requires monitoring of deployed SPoC environments ⓘ
protection of PIN from compromise on COTS device ⓘ
secure lifecycle management of the SPoC solution ⓘ
secure update mechanisms for the PIN entry application ⓘ
segregation of sensitive functions from general-purpose mobile OS ⓘ
tamper detection and response mechanisms in the solution ⓘ
requiresUseOf secure PIN entry application ⓘ
trusted card reader ⓘ
scope card-present PIN-based transactions ⓘ
usedBy acquirers and processors ⓘ
payment service providers ⓘ
solution providers offering PIN on mobile solutions ⓘ

How these facts were elicited

Referenced by (2)

Full triples — surface form annotated when it differs from this entity's canonical label.

PTS → relatedTo → PCI SPoC ⓘ
PCI CPoC → relatedTo → PCI SPoC ⓘ