Know Better. See how a flexible issuing
platform and loyalty expertise build valuable relationships. Find a range of
customizable payments solutions. Access cutting-edge technology and innovative products. See how exceptional insight and support make these solutions
work for you.
Know Better. Know the assurance
of the industry’s only 100% authorization process. Experience our dedication to fraud protection and security. Benefit from Discover Network’s role in the Payment Card Industry Data Security Standards initiative, including access to guidance and support from Discover Network.
Know Better. Literally. Keep in better touch with business trends. Get quick
references to best practices. Look for breaking business news. Find tools and services that help
to keep your business more agile, informed and capable.
Know Better. Find the tools you need to make Discover Network a more powerful asset for you. Gain guidance, collaboration and expertise. Keep up
with operating regulations.
Know Better. Tap into the expertise of Discover Network. Find clear, straightforward answers to your questions. Know that you can depend on us to help you move your business forward.
Data security is a top priority for Discover Network. The Discover Information Security & Compliance (DISC) program was developed to implement and maintain efficient data security requirements and procedures for its constituents and promote the adoption of secure transaction processing of cardholder data on the Discover Network.
As part of this ongoing initiative, Discover Network partnered with other major payment card brands to form the Payment Card Industry Security Standards Council, LLC (“PCI SSC”). PCI SSC was launched on September 7, 2006 to manage the ongoing evolution of the Payment Card Industry Data Security Standard (“PCI DSS”), which focuses on improving payment account security throughout the transaction process. With the launch of PCI SSC, Discover Network, along with the other major payment card brands, adopted a single security standard, the PCI DSS, as the security requirement for all entities that process, store or transmit cardholder data. Discover Network is firmly committed to a single data protection standard for the payment card industry. The DISC program is designed to enforce compliance to the requirements of the PCI DSS by helping you safeguard cardholder data and limit data compromises.
PCI DSS is a multifaceted security standard that includes requirements for security management, policies and procedures, network architecture, software design and other critical protective measures. The PCI DSS consists of twelve requirements which are organized into six logically related control objectives. Click here to download a complete copy of the PCI DSS.
Consistent with the PCI DSS, you should never store sensitive authentication data post-authorization. In addition, if cardholder data is retained post-authorization, it must be secured according to the requirements outlined in the PCI DSS.
* These data elements must be protected if stored in conjunction with the PAN. This protection must be consistent with the PCI DSS requirements for general protection of the cardholder environment. Additionally, other legislation (for example, related to consumer personal data protection, privacy, identity theft, or data security) may require specific protection of this data, or proper disclosure of a company's practices if consumer-related personal data is being collected during the course of business. PCI DSS; however, does not apply if PANs are not stored, processed, or transmitted. ** Sensitive authentication data must not be stored subsequent to authorization (even if encrypted).
Data Security Roles
For More Information
To learn more about the DISC program, please contact Discover Network via email at askdatasecurity@discover.com
Data Security is a top priority for Discover Network. To that end, Discover Network is committed to supporting the PCI
DSS as the single data security standard for the payment card industry. As part of our ongoing security initiatives,
Discover Network - together with the other major payment card brands - adopted the Payment Card Industry Data Security
Standard (“PCI DSS”) as the security requirement for Discover Network service providers. Service providers are third
party organizations that process, store or transmit Discover Network cardholder data on behalf of Discover Network
merchants, acquirers, or other parties. Service providers include, but are not limited to, Third Party Processors
and Payment Service Providers. Discover Network requires all service providers that process, store or transmit
Discover Network cardholder data to comply with the PCI DSS.
Service providers that process, store or transmit Discover Network cardholder data are required to comply with
the PCI DSS at all times. When validating compliance to the PCI DSS, service providers may contract with a
Qualified Security Assessor (QSA) to perform their compliance assessments or perform a self-assessment. All
self-assessments must be performed using the applicable PCI DSS Payment Card Industry Self-Assessment
Questionnaire and must be certified by an authorized officer of the service provider. The
PCI SSC website
contains the following useful information when validating compliance to the PCI DSS:
PCI DSS
PCI DSS Security Audit Procedures
PCI DSS Payment Card Industry Self-Assessment Questionnaire (SAQ)
List of Approved Scanning Vendors (ASV)
List of Qualified Security Assessors (QSA)
Discover Network may require service providers to report their compliance status on an annual basis, or upon
request from Discover Network. Service providers that performed a self-assessment may report their compliance
status by submitting the applicable SAQ Attestation of Compliance to Discover Network. Service providers that
contracted with a QSA may report their compliance status using the
DISC Attestation of Compliance form. This two page form allows service providers to communicate their
compliance status to Discover Network by completing the form and having an authorized officer of the company
sign the completed document. Instructions for submitting this information to Discover Network are included
within the form.
Here are a few tips to assist you with your compliance efforts:
Verify that you are not storing sensitive authentication data. Storage of sensitive authentication data
is never permitted.
Verify that your Point of Sale systems are not storing sensitive authentication data and are protecting
cardholder data according to the PCI DSS.
Take the necessary steps to protect cardholder data according to the PCI DSS.
Know your business partners – verify that your service providers are protecting cardholder data in
accordance with the PCI DSS.
Please keep in mind that completing quarterly external vulnerability scans is only one of the PCI
DSS requirements. Discover Network service providers are responsible for complying with all the PCI DSS
requirements.
In the event that you become aware of a suspected or actual data security breach of Discover Network
cardholder data you must follow the procedures in the applicable Discover Network agreement or operating
regulations, including the following:
Notify Discover Network immediately by calling (800) 347-3083.
Work with Discover Network and investigators to conduct a thorough assessment of the data security breach.
Provide Discover Network with any and all information and follow all instructions of Discover Network
representatives regarding the data security breach.
For More Information
To learn more about the DISC program, please contact Discover Network via e-mail at askdatasecurity@discover.com.
In order to protect the integrity of cardholder data, Discover Network has implemented the Payment Card Industry Data
Security Standard (“PCI DSS”) as the security requirements for Discover Network Merchants. Discover Network requires
all merchants that process, store or transmit Discover Network Cardholder data to comply with the PCI DSS. In addition,
merchants may also be required to validate their compliance directly to Discover Network or to their Acquirer.
Discover Network Merchants are required to comply with the PCI DSS at all times. When validating compliance
to the PCI DSS, merchants may contract with a Qualified Security Assessor (QSA) to perform their compliance
assessments or perform a self-assessment. All self-assessments must be performed using the applicable PCI DSS
Payment Card Industry Self-Assessment Questionnaire (SAQ) and must be certified by an authorized officer of the
merchant. The PCI SSC website contains
the following useful information when validating compliance to the PCI DSS:
PCI DSS
PCI DSS Security Audit Procedures
PCI DSS Payment Card Industry Self-Assessment Questionnaire
List of Approved Scanning Vendors (ASV)
List of Qualified Security Assessors (QSA)
Discover Network may require merchants to report their compliance status on an annual basis, or upon request
from Discover Network. Merchants that performed a self-assessment may report their compliance status by
submitting the applicable SAQ Attestation of Compliance to Discover Network. Merchants that contracted with
a QSA may report their compliance status using the
DISC Attestation of Compliance form.
This two page form allows merchants to communicate their compliance status to Discover Network by completing the
form and having an authorized officer of the company sign the completed document. Instructions for submitting
this information to Discover Network are included within the form.
Here are a few tips to assist you with your compliance efforts:
Verify that you are not storing sensitive authentication data. Storage of sensitive authentication data is never permitted.
Verify that your Point of Sale systems are not storing sensitive authentication data and are protecting cardholder data according to the PCI DSS.
Take the necessary steps to protect cardholder data according to the PCI DSS.
Know your business partners – verify that your service providers are protecting cardholder data in accordance with the PCI DSS.
Please keep in mind that completing quarterly external vulnerability scans is only one of the PCI DSS requirements. Discover Network Merchants are responsible for complying with all the PCI DSS requirements.
In the event that you become aware of a suspected or actual data security breach of Discover Network cardholder data you must follow the procedures in the applicable Discover Network agreement or operating regulations, including the following:
Notify Discover Network immediately by calling (800) 347-3083.
Work with Discover Network and investigators to conduct a thorough assessment of the data security breach.
Provide Discover Network with any and all information and follow all instructions of Discover Network representatives regarding the data security breach.
For More Information
To learn more about the DISC program, please contact Discover Network via e-mail at askdatasecurity@discover.com.