The Tokenization System Is Considered Part of an Entity's Cardholder Data Environment (Cde), and Must Be Adequately Segmented (Isolated) from All Networks Not...
The tokenization system is considered part of an entity's cardholder data environment (CDE), and must be adequately segmented (isolated) from all networks not in scope for PCI DSS.
What does cardholder data consist of?
Cardholder data (CD) is any personally identifiable information (PII) associated with a person who has a credit or debit card. Cardholder data includes the primary account number (PAN) along with any of the following data types: cardholder name, expiration date or service code.
Payment Card Industry Data Security Standard (PCI DSS) & Tokenization. Fortunately, tokenization is a PCI-approved method of protecting payment card industry data and is authorized by the PCI Security Standards Council (SSC) to use in pursuit of PCI Compliance.