Cardholder Data PAN Masking Desktop Audit
Cardholder Data PAN Masking Desktop Audit
Inspection template to verify that the agent desktop application masks Primary Account Numbers (PANs) after entry and displays only the permitted digits based on user role and access level, in alignment with PCI DSS PAN display requirements.
Inspection Scope and Environment
-
Application and workstation identified
Record the application name, workstation ID, environment (production/UAT), and date/time of inspection.
-
Inspector confirmed user role under test
Select the role used for the audit to verify role-based PAN display permissions.
-
Test cardholder data source approved
Confirm that test PAN data used for the inspection is authorized and does not expose real cardholder data unnecessarily.
-
Inspection scope limited to PAN display controls
Confirm the audit is focused on PAN masking and permitted digit display behavior rather than unrelated application functions.
-
Reference standard reviewed
Verify against PCI DSS PAN display expectations: Primary Account Numbers must be masked when displayed, with only the permitted digits visible based on business need and role.
PAN Entry and Masking Behavior
-
PAN is masked immediately after entry
After the card number is entered, the application displays a masked value instead of the full PAN.
-
Only permitted digits are visible
Confirm the display shows only the allowed digits for the role, such as last four digits or another approved limit.
-
Masking format matches approved standard
Record the observed masking format, such as ************1234, and compare it to the approved masking rule.
-
Full PAN not visible in any field on screen
Verify the full card number is not visible in entry fields, confirmation panels, pop-ups, or summary views.
Role-Based Display Controls
-
Role-based masking rules enforced
Confirm the application applies the correct PAN display rule for the selected role.
-
Privileged role visibility limited to approved digits
If the role has elevated access, verify the visible digits still remain within approved business and PCI limits.
-
Unauthorized role cannot reveal additional PAN digits
Confirm the user cannot expand, unmask, copy, or otherwise reveal additional PAN digits without approved authorization.
-
Access control exceptions documented
Document any approved exception, temporary access, or compensating control related to PAN visibility.
Evidence, Logging, and Data Exposure Checks
-
No full PAN visible in logs or audit trail
Verify that application logs, audit events, and transaction history do not display the full PAN.
-
No full PAN visible in screenshots or remote support tools
Confirm that screen capture tools, remote assistance sessions, and shared views do not expose unmasked card numbers.
-
Evidence captured for masked display state
Attach a screenshot or photo showing the masked PAN display and the role context used for the test.
-
Deficiencies and corrective actions recorded
Document any non-conformance, including affected screen, role, observed exposure, and required remediation.
Ask AI
Template Studio