In accordance with card payments security standards an invoice should never include a full card primary account number (BT-87). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.
The normalized value of ID contains more than ten characters. An invoice must not contain a full card number; under the stated security guidance, no more than ten digits should be shown.
The limit protects the card number by preventing the full primary account number from appearing on the invoice.
The card identifier in the invoice is longer than ten characters. Shorten the identifier so that the invoice does not contain a full card number.
- Locate the card identifier in
ApplicableTradeSettlementFinancialCard/ID. - Limit its normalized value to no more than ten characters.
- Generate the invoice again and validate it again.
<ram:ApplicableTradeSettlementFinancialCard> <ram:ID>123456789012</ram:ID> </ram:ApplicableTradeSettlementFinancialCard>
<ram:ApplicableTradeSettlementFinancialCard> <ram:ID>1234567890</ram:ID> </ram:ApplicableTradeSettlementFinancialCard>
Technical details
The test applies normalize-space to ID and checks that the resulting string length is no greater than ten.
The rule applies to the card identifier ID within ApplicableTradeSettlementFinancialCard.
rule/@context)assert/@test)