Authorization

PCIComplianceHubLast updated

In access control, the granting of rights to a user, program or process, which decides what an authenticated identity may do. In a payment, the process that ends when the merchant receives a response to the transaction, an approval or a decline. PCI DSS uses the word in both senses, and the context says which.

Applies to. The access-control sense applies to every account on an in-scope system: authentication says who, authorisation says what they may do. The transaction sense is the boundary Requirement 3 draws around sensitive authentication data.
Example. A support analyst authenticates with a password and a one-time code, then is authorised to view masked card numbers but not to export them. Separately, a customer's card is authorised at checkout; once that response arrives, the card verification code must be unrecoverable (3.3.1).
Limits. The two senses are easy to run together and the consequences differ. Authorisation of access is governed by Requirement 7: a defined access control model (7.2.1), assignment by job function (7.2.2), and documented approval by authorised personnel (7.2.3). Authorisation of a transaction is the moment after which storing SAD is prohibited (3.3.1) and before which it must be encrypted (3.3.2).
In PCI DSS v4.0.1. 7.2.1, 7.2.2, 7.2.3, 3.3.1