Full-Disk Encryption (FDE)
PCIComplianceHubLast updated
Encryption of an entire storage drive, including the operating system, applications and data, so the contents are unreadable without the decryption key. FDE protects against physical loss or theft of a device and little else: once the system has booted and a user has authenticated, the data is transparently decrypted for anything running on that system. PCI DSS therefore restricts disk-level encryption as a means of rendering a stored primary account number unreadable. It is permitted on removable media, but on non-removable storage the PAN must also be rendered unreadable by another mechanism meeting Requirement 3.5.1, because logical access by an authenticated user or a compromised process defeats it entirely.