In a tokenization system used to meet PCI DSS requirements, what must be true of the token value itself?
-
A
It must be encrypted with AES-256
-
B
It must have no exploitable relationship to the original PAN
-
C
It must be exactly 16 digits like a real PAN
-
D
It must be stored in the same database as the PAN