TechTarget.com/searchsecurity

https://www.techtarget.com/searchsecurity/definition/cardholder-data-environment-CDE

cardholder data environment (CDE)

By Rahul Awati

What is a cardholder data environment (CDE)?

A cardholder data environment (CDE) is a computer system or networked group of IT systems that process, store or transmit cardholder data or sensitive payment authentication data. A CDE also includes any component that directly connects to or supports this network.

The Payment Card Industry Data Security Standard (PCI DSS) defines a CDE as "the people, processes, and technologies that store, process, or transmit, cardholder data or sensitive authentication data [SAD]."

A cardholder refers to any person who receives a payment card (credit or debit) from a card-issuing company and is authorized to use it. Cardholder data refers to the information that identifies the cardholder, is printed on the card, and lets the issuer track accounts. The data includes a unique card number that identifies both the card issuer and card user, and the cardholder name, card issuing date, expiry date and service code (if provided).

When the cardholder makes a payment using that card, numerous entities are involved in processing the card to facilitate the transaction and complete the payment. Some entities may also store the cardholder data or transmit it to other entities. Together, all these entities that are exposed to cardholder data and involved in authenticating the cardholder via "secret" information -- like a personal identification number (PIN) or CVV code -- constitute the CDE. The more entities that are part of the CDE, the greater the "scope" of the CDE.

IThe PCI DSS specifies what kind of cardholder data can or cannot be stored in the CDE. Generally, data about the cardholder, including their name and card number, can be stored in the CDE, but SAD like the PIN number or CVV cannot be stored. Not storing SAD in the CDE limits the risk of fraud since it prevents a malicious actor from accessing the authentication information required to complete an unauthorized transaction.

Examples of entities in a cardholder data environment

Examples of entities that may be part of a particular CDE include the following:

The need to protect the cardholder data environment

Different organizations may own or operate the various entities that constitute a cardholder's environment. Since all these entities are involved in processing a cardholder's data, they must all be secured to prevent the data from falling into the wrong hands. If a cybercriminal can access sensitive cardholder data, they might execute fraudulent transactions on that card or steal the cardholder's identity.

To avoid such situations, all organizations that collect, process or store cardholder holder and have entities that are part of the CDE must implement measures to protect the CDE. In doing so, they can better protect cardholders from fraud and identity theft as well as comply with the PCI DSS.

Securing CDE entities for PCI DSS compliance

The PCI DSS includes specific requirements for securing electronic payment and authentication data residing on all physical and virtual components in the CDE:

Most data breaches in the retail sector involve a compromise of the CDE. PCI DSS requires various controls to secure the CDE. The idea of one such control, network segmentation, is that if the size and scope of the CDE is minimal and is adequately isolated from other parts of the network using technology and rule sets, this will reduce the likelihood of a data breach.

Besides segmentation, the PCI DSS requires organizations to implement these measures to protect the CDE:

Learn more about the best practices for complying with the new PCI DSS 4.0. Explore best practices and tactics to prevent a data breach, and check out how cybercriminals steal credit card information.

14 Nov 2023

All Rights Reserved, Copyright 2000 - 2025, TechTarget | Read our Privacy Statement