Merchant Processes and CID/CVV2
I recently received a letter from the company that monitors my home alarm. It basically stated that to avoid a $3US surcharge that I must opt out of receiving bill in the mail (which is fine) and that I must set up automatic transactions. I also found this form attached.
This is not the first time that I have seen a payment option that includes a requirement for the CVV2 or CID value from my credit card. However with a little knowledge of PCI, I have to ask myself the following question, “What exactly are they going to do with this information?” According to PCI-DSS, this information must not be stored (even in an encrypted format) after authorization.
That raises the following questions for the merchant requiring this information–
- Is this truly only for the first transaction authorization and the physical form will be securely destroyed?
- In this particular case, this is for a monthly transaction. So their relationship with their provider is such that CID/CVV is optional (and not used) for secondary transactions?
- Or is this information being stored, electronically or physically, allowing for the possibility of later transactions?
In this Continue reading


Operators don't want TM Forum to get lost in NFV technicalities. They want the focus on making money.
What's the latest on intent-based networking--the hot new topic in SDN.
Intel boosts IoT for cars; former Cisco and Time Warner CTOs intersect; Khosla Ventures funds Gitlab.
Brocade's Jon Hudson sat down with SDxCentral to discuss the current and future state of SDN, NFV, and DevOps.
Join the September 25th Cisco DemoFriday and learn how you can benefit from network programmability as you transition from legacy systems to open standard interfaces.
Achieve the “big bang” transformation.
Is it the end for MPLS? Cato claims it's got a way to give MPLS-like performance to Internet links.