3.4 Access to displays of full PAN and ability to copy PAN is restricted
How to meet it
Mask PAN on display (show at most first six/last four) except for those with a need.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 3.4, in plain English.
3.4.1When PAN is displayed it is masked so at most the BIN and last four digits show, and only those with a business need may see more.
3.4.2When remote-access technologies are used, technical controls block copying or relocating PAN except for those with explicit authorization.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Physical and environmental security policyUse for ISO 27001 A.7.1 to A.7.14, SOC 2 Security, and PCI DSS requirement 9 physical access controls.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Endpoint and mobile device policyUse for ISO 27001 A.6.7, A.7.9, A.8.1, malware protection, remote work, and SOC 2 endpoint controls.
Open the control-to-policy map← 3.3 Sensitive authentication data (SAD) is not stored after authorisation3.5 PAN is secured wherever it is stored →
Back to Requirement 3, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.