AS 2805.3-2000
Superseded
A superseded Standard is one, which is fully replaced by another Standard, which is a new edition of the same Standard.
View Superseded by
Electronic funds transfer - Requirements for interfaces - PIN management and security
Hardcopy , PDF 1 User , PDF 3 Users , PDF 5 Users , PDF 9 Users
25-07-2024
English
01-01-2000
Specifies minimum requirements for protecting the personal identification number (PIN), used as a means of verifying the identity of a customer within an electronic funds transfer (EFT) network, against unauthorized disclosure, compromise, and misuse throughout its life cycle, and in so doing, to minimize the risk of fraud occurring within EFT systems.
Committee |
IT-005
|
DocumentType |
Standard
|
ISBN |
0 7337 3357 3
|
Pages |
22
|
PublisherName |
Standards Australia
|
Status |
Superseded
|
SupersededBy | |
Supersedes | |
UnderRevision |
This Standard specifies the minimum security measures required for effective PIN management. Standard means of interchanging PIN data are provided. This Standard does not cover the following:(a) The protection of the PIN against loss or intentional misuse by the customer or authorized employees of the issuer.(b) Privacy of non-PIN transaction data (see AS 2805.9).(c) Protection of transaction messages against alteration or substitution, e.g. an authorization response to a PIN verification (see AS 2805.4).(d) Protection against replay of the PIN or transaction.(e) Specific key management techniques (see AS 2805.6 series).(f) PIN management and security for transactions conducted using integrated circuit cards (ICC).(g) The use of asymmetric encipherment algorithms for PIN management.NOTE: For a detailed discussion on the need for personal identification number (PIN) protection, see Appendix A.(h) Physical and logical security (see AS 2805.14.1).NOTE: Further information on PIN management for security is given in Appendices A and C.
First published as AS 2805.3-1985.
Second edition 2000.
AS 2805.5.4-2000 | Electronic funds transfer - Requirements for interfaces Ciphers - Data encipherment algorithm 3 (DEA 3) and related techniques |
AS 3523-1988 | Identification cards - Numbering system and registration procedure for issuer identifiers |
AS 2805.5.2-1992 | Electronic funds transfer - Requirements for interfaces - Ciphers Modes of operation for an n-bit block cipher algorithm |
AS 2805.9-1991 | Electronic funds transfer - Requirements for interfaces - Privacy of communications |
AS 2805.9-2000 | Electronic funds transfer - Requirements for interfaces Privacy of communications (Reconfirmed 2013) |
AS 2805.14.1-2000 | Electronic funds transfer - Requirements for interfaces Secure cryptographic devices (retail) - Concepts, requirements and evaluation methods |
AS 2805.4-1985 | Electronic funds transfer - Requirements for interfaces - Message authentication |
AS 2805.6.3-2000 | Electronic funds transfer - Requirements for interfaces Key management - Session keys - Node to node (Reconfirmed 2013) |
AS 2805.6.6-2006 | Electronic funds transfer - Requirements for interfaces Key management - Session keys - Node to node with KEK replacement |
AS 2805.6.2-2002 | Electronic funds transfer - Requirements for interfaces Key management - Transaction keys (Reconfirmed 2013) |
AS 3769-1990 | Automatic teller machines - User access |
AS 2805.8-1986 | Electronic funds transfer - Requirements for interfaces - Financial institution message content |
AS 2805.6.1-2002 | Electronic funds transfer - Requirements for interfaces Key management - Principles |
AS 2805.7-1986 | Electronic funds transfer - Requirements for interfaces - POS message content |
AS 2805.6.4-2001 | Electronic funds transfer - Requirements for interfaces Key management - Session keys - Terminal to acquirer |
AS 2805.6.4-2006 | Electronic funds transfer - Requirements for interfaces Key management - Session keys - Terminal to acquirer |
Access your standards online with a subscription
Features
-
Simple online access to standards, technical information and regulations.
-
Critical updates of standards and customisable alerts and notifications.
-
Multi-user online standards collection: secure, flexible and cost effective.