The PCI DSS requirementRequirement 4.1 states ?usethat strong cryptography and security protocols suchmust asbe SSL / TLS/ IPSECused to safeguard sensitive cardholder data during transmission over open, public networks.? While the PCI DSS does not specifically mentionnetworks. Bluetooth technology is included in Requirement 4.1 as an example of an open, public network, itand iscardholder adata technologysent thatover canBluetooth presentmust securitytherefore riskbe if not implemented properly. Appropriate measuresprotected in theaccordance implementationwith ofthis the Bluetooth technology must be taken such as having the security features enabled and using long PIN codes or pairing the devices only in private. PCI SSC recommends that you consult a Qualified Security Assessor for proper implementation of the Bluetooth technology. Our list of Qualified Security Assessors can be found at: https://www.pcisecuritystandards.org/resources/qualified_security_assessors.htm Please note:requirement. If a vendorBluetooth implementation is providingunable anto applicationmeet thatstrong iscryptography,
compensating facilitatingcontrols thewill transmissionneed ofto thebe implemented to prevent unauthorized access to Bluetooth transmissions to capture cardholder transaction using Bluetooth technology, that vendor is responsible for meeting the PCI DSS requirements, not the consumer.data.