Archiving cases
If you enable case investigation, configure cases to be archived no later than the end of the retention period.
Cardholder data must be securely deleted after the retention period ends. For more information about defining the retention period, see Installation prerequisites.
- In the user interface, click the Administration tab.
- Select from the navigation menu.
- Click the Investigation & queries tab. Click the Case Investigation checkbox.
- In the Archive cases after (days) field, you must enter a value that is equal or smaller to the retention period that you defined.
According to PCI DSS requirement 3.5.1, PANs must be rendered unreadable anywhere that they are stored. Case attachments are stored decrypted. You must implement proper operational procedures to ensure that no PANs or other sensitive data are stored in a case attachment or you must disable case attachments.