Personal identification number (PIN)

Click to enlargeAutomated Teller Machine (ATM) and Point-of-Sale (POS) technology are popular worldwide. These payment options offer convenience for shoppers, guaranteed payment for merchants (in the case of a POS system) and incremental revenue for banks and networks. At the same time, the easy access offers a tempting occasion for invasion and pilfering on the part of unscrupulous people.

A three-part International Standard reduces the opportunity for a breach in security and provides a high probability of detection of any unauthorized disclosure of personal identification numbers (PIN). ISO 9564 provides instructions to financial institutions in the development, implementation and/or the operation of systems and procedures for the protection of PINs throughout their lifecycle.

The primary benefit of ISO 9564 is the establishment of a baseline security framework for the management of cardholder PINs in interchange systems. The standard is designed so that issuers of PIN authenticated payment cards can have confidence that their personal information numbers are being uniformly protected while under the control of other institutions and participants in the payment system.

Related standards

  • ISO 9564-1:1991
    Banking -- Personal Identification Number management and security -- Part 1: PIN protection principles and techniques
  • ISO 9564-1:2002
    Banking -- Personal Identification Number (PIN) management and security -- Part 1: Basic principles and requirements for online PIN handling in ATM and POS systems