Table of Contents

PCI-DSS refers to the credit card industries security compliance process for credit card merchants and software providers. More information on PCI-DSS on their offical website here.

Control version 4.0 was the first version to meet the general conditions for PCI-DSS certification, however official (external) certification was not sought until Control 4.4.

Changes to Credit Card Processing

Control 4.0 implemented secure credit cards storage and restricted information (VCodes), but Cyrious chose to implement a more comprehensive security model with Control 4.4.

Changes to Credit Card Storage

TDES Keys

TDES utilizes a trinary key system. Each of these keys is necessary to encrypt and decrypt the information. These keys are supplied as follows:

New Credit Card Options

Several new credit card options were required for PCI compliance.

The access to the credit card system is only as secure as the login for anyone with legitimate access to the same information. Control required several changed to fully meet PCI recommendations and requirements for user login security.