Frequently Asked Question
															What types of 3DS components are in scope for Requirement P2-7 in the PCI 3DS Core Security Standard?
Requirements P2-7.1 and P2-7.2, which relate to data center and CCTV security, apply to 3DS Directory Server (DS) and 3DS Access Control Server (ACS) systems. 
As noted in the Overview section of Requirement P2-7, the DS and ACS systems are critical components of the 3DS infrastructure that require a secure facility with elevated physical security controls to restrict, manage, and monitor all physical access.
The requirements in P2-7 are recommended, but not required, for locations where only a 3DS Server (3DSS) is present. Refer to the PCI 3DS Core Security Standard for information about the different 3DS components.
 
As noted in the Overview section of Requirement P2-7, the DS and ACS systems are critical components of the 3DS infrastructure that require a secure facility with elevated physical security controls to restrict, manage, and monitor all physical access.
The requirements in P2-7 are recommended, but not required, for locations where only a 3DS Server (3DSS) is present. Refer to the PCI 3DS Core Security Standard for information about the different 3DS components.
December 2020
Article Number: 1488
Related
- 
										Are Approved Scanning Vendors and Qualified Security Assessors considered third-party service providers for PCI DSS Requirements 12.8 and 12.9?
										
 - 
										What are the expectations for entities when assigning risk rankings to vulnerabilities and resolving or addressing those vulnerabilities?
										
 - 
										Is phishing-resistant authentication alone acceptable as multi-factor authentication for PCI DSS Requirements 8.4.1 and 8.4.3?
										
 
Featured FAQ Articles
Featured
- 
									
										Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?									
									
 - 
									
										Is the PCI DSS Attestation of Compliance intended to be shared?									
									
 - 
									
										How does an entity report the results of a PCI DSS assessment for new requirements that are noted in PCI DSS as best practices until a future date?									
									
 - 
									
										Where do I direct questions about complying with PCI standards?									
									
 - 
									
										Can SAQ eligibility criteria be used as a guide for determining applicability of PCI DSS requirements for merchant assessments documented in a Report on Compliance?									
									
 
Most Popular
- 
									
										Are Approved Scanning Vendors and Qualified Security Assessors considered third-party service providers for PCI DSS Requirements 12.8 and 12.9?									
									
 - 
									
										What are the expectations for entities when assigning risk rankings to vulnerabilities and resolving or addressing those vulnerabilities?									
									
 - 
									
										Is phishing-resistant authentication alone acceptable as multi-factor authentication for PCI DSS Requirements 8.4.1 and 8.4.3?									
									
 - 
									
										Are passkeys synced across devices, implemented according to the FIDO2 requirements, acceptable for use as phishing-resistant authentication to meet PCI DSS Requirement 8.4.2?									
									
 - 
									
										How should PCI DSS v4.x requirements noted as superseded by another requirement be reported after 31 March 2025?									
									
 
Most Recently Updated
- 
									
										Can unencrypted PANs be sent over e-mail, instant messaging, SMS, or chat?									
									
 - 
									
										Are entities allowed to request that cardholder data be provided over end-user messaging technologies?									
									
 - 
									
										Does PCI DSS allow faxing of payment card numbers?									
									
 - 
									
										What is the maximum period of time that cardholder data can be stored?									
									
 - 
									
										To which devices does PCI DSS Requirement 10.4.2 apply?