Skip to content

PCI DSS v4.0 Req 3.2-3.4: PAN to last 4 only

Source: 03-pci-dss-scope-reduction.phisql (spec v1.0)

PhiSQL

-- PCI DSS v4.0 Req 3.2-3.4: PAN to last 4 only.
-- Demonstrates a WHERE predicate using CONFIDENCE. High-confidence card numbers
-- keep their last four digits; every other detected card number is fully
-- redacted by the final statement, which has no WHERE. Without it, a card
-- number at or below the threshold would be left unchanged (RFC #57).
-- Compiles to 03-pci-dss-scope-reduction.json.

POLICY pci_dss_scope_reduction
  DESCRIPTION 'PCI DSS v4.0 Req 3.2-3.4: PAN to last 4, with full redaction below the confidence threshold.';

REDACT CREDIT_CARD WITH LAST_4 WHERE CONFIDENCE > 0.85;
REDACT CREDIT_CARD WITH REDACT;

Compiles to

{
  "metadata": {
    "description": "PCI DSS v4.0 Req 3.2-3.4: PAN to last 4, with full redaction below the confidence threshold."
  },
  "identifiers": {
    "creditCard": {
      "creditCardFilterStrategies": [
        {
          "strategy": "LAST_4",
          "condition": "confidence > 0.85"
        },
        {
          "strategy": "REDACT"
        }
      ]
    }
  }
}