# PCI PTS POI Device Security Requirements v6

Framework id: `pci_pts`. Payment Security. Publisher: PCI Security Standards Council. Version: 6. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.pcisecuritystandards.org/document_library/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (12, average coverage 77%)
- A Device Physical Security — tamper evidence, tamper response, and physical penetration resistance: PE-03, PE-04, PE-05, PE-06, PE-19, PE-20, SR-09, SR-10, SR-11 (72%)
- B Logical Security — firmware integrity, secure boot, runtime protections, and debug interface controls: SI-07, CM-03, CM-05, CM-14, SC-34, SI-16, SA-10 (75%)
- C PIN Entry Device Requirements — PIN pad security, PIN block formatting, and display/keypad isolation: IA-02, IA-07, PE-04, SC-13, SC-28 (55%)
- D Key Management — PIN encryption key lifecycle, key injection, DUKPT/AES key schemes, and key loading security: SC-12, SC-13, SC-17, PE-03, PE-18 (88%)
- E Communication Security — device-to-host encryption, TLS requirements, and communication channel integrity: SC-07, SC-08, SC-12, SC-13, SC-23, AC-17, AC-04 (90%)
- F Software Security Requirements — application separation, privilege isolation, and secure update mechanisms: SA-08, SA-10, SA-11, SA-15, SA-17, CM-03, CM-14, SI-02, SI-07 (85%)
- G Integration and Assembly Security — secure manufacturing, component provenance, and anti-counterfeiting: SR-01, SR-02, SR-03, SR-05, SR-06, SR-09, SR-10, SR-11, SR-12, SA-04 (60%)
- H Vendor Qualification and Development Practices — secure development environment, personnel security, and quality assurance: SA-03, SA-04, SA-09, SA-15, SA-16, SA-21, PS-03, PS-06, PS-07 (75%)
- I Unattended Payment Terminal (UPT) Requirements — kiosk security, anti-skimming, and remote monitoring: PE-03, PE-06, PE-20, SC-08, SI-04, SR-09, SR-10, AC-17 (68%)
- J Open Protocol Requirements — contactless interface security, NFC protocol protection, and kernel isolation: SC-08, SC-13, SC-40, AC-18, AC-04, SI-04 (78%)
- K Device Management Lifecycle — provisioning, deployment, maintenance, decommissioning, and key destruction: CM-02, CM-03, CM-08, CM-09, MA-02, MA-03, MA-04, MA-06, MP-06, SR-12 (85%)
- L Accountability and Audit — event logging, tamper event recording, and device integrity attestation: AU-02, AU-03, AU-06, AU-09, AU-12, SI-04, SI-07 (90%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=pci_pts
- Control-to-clause mappings as JSON: /api/v1/frameworks/pci_pts?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/pci-pts.json
- Page for people: /frameworks/pci-pts/
