# What is Point-of-Sale (POS) Security?

> Point-of-sale (POS) security protects the devices, applications, networks, data, people, and services used to record sales and accept payment at checkout.

- Canonical URL: https://yellowcube.eu/glossary/point-of-sale-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Its scope can include tills, card readers, mobile terminals, POS software, store networks, back-office systems, remote-management tools, payment processors, support providers, and the physical environment around each device.

Controls should protect payment account data and other retail information while preserving transaction availability. Requirements depend on payment methods, data flows, software and terminal models, acquiring relationships, third parties, and the assessed cardholder data environment.

### Key points

- **Transaction path:** Identify where payment and customer data enters, flows, is stored, or can be affected, including management systems, integrations, support access, wireless links, and connected systems.
- **Device and data protection:** Use supported terminals and software, inspect for tampering or substitution, avoid unnecessary storage, protect keys, and follow instructions for any listed point-to-point encryption solution.
- **Operational controls:** Change unsafe defaults, strongly authenticate remote access, separate duties, segment where effective, apply tested updates, monitor activity, train staff, and coordinate incident procedures with payment partners.
- **Important limitation:** An approved terminal, encrypted transaction, or PCI DSS validation does not prove the whole POS environment secure. A PCI-listed point-to-point encryption (P2PE) solution can reduce applicable PCI DSS requirements when implemented as validated, but it does not eliminate merchant responsibilities or address malware, stolen credentials, unsafe integrations, device substitution, and later changes.

### Related terms

[Payment Card Industry Data Security Standard (PCI DSS)](<https://yellowcube.eu/glossary/payment-card-industry-data-security-standard/>) · [Data security](<https://yellowcube.eu/glossary/data-security/>) · [Endpoint security](<https://yellowcube.eu/glossary/endpoint-security/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>)

### Sources

[PCI Security Standards Council, PCI Data Security Standard](https://www.pcisecuritystandards.org/standards/pci-dss/) · [PCI SSC FAQ 1301, Payment Terminals in a PCI DSS Assessment](https://www.pcisecuritystandards.org/faqs/1301/) · [PCI SSC, Point-to-Point Encryption (P2PE)](https://www.pcisecuritystandards.org/standards/point-to-point-encryption-p2pe/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

