Token

Also: Authentication token, Hardware token

PCIComplianceHubLast updated

In authentication, a value produced by a hardware device or a piece of software that works with an authentication server or a VPN to prove possession: the something-you-have factor. A key fob showing six digits, an authenticator app and a smart card are all tokens in this sense; a payment token, which replaces a PAN, is a different thing with the same name.

Applies to. Every entity using a possession factor for multi-factor authentication, which 8.4 requires for administrative access into the CDE and for all remote access.
Example. An administrator's login asks for a password and then the code from a hardware token. Two factors of different types, which 8.3.1 recognises and 8.5.1 requires the MFA system to insist on.
Limits. A token proves possession of the token, not the identity of the holder, which is why it is one factor and not two. 8.5.1 requires the MFA system to resist replay, so a code that can be reused after interception does not qualify. The Council's glossary reserves this term for authentication; tokens that stand in for PANs are index tokens and payment tokens, governed by Requirement 3.
In PCI DSS v4.0.1. 8.3.1, 8.5.1