Archiving cases

If you enable case investigation, configure cases to be archived no later than the end of the retention period.

Cardholder data must be securely deleted after the retention period ends. For more information about defining the retention period, see Installation prerequisites.

  1. In the user interface, click the Administration tab.
  2. Select System > Configuration from the navigation menu.
  3. Click the Investigation & queries tab. Click the Case Investigation checkbox.
    Figure 1. Case investigation settings section
    This image is explained in the surrounding text.
  4. In the Archive cases after (days) field, you must enter a value that is equal or smaller to the retention period that you defined.

According to PCI DSS requirement 3.5.1, PANs must be rendered unreadable anywhere that they are stored. Case attachments are stored decrypted. You must implement proper operational procedures to ensure that no PANs or other sensitive data are stored in a case attachment or you must disable case attachments.