Tokenisation
Replacing a sensitive value, such as a card number, with a meaningless token while the real value is held in a separate secured vault; widely used to reduce PCI DSS scope.
Tokenisation replaces a sensitive value, such as a payment card number, with a substitute value called a token that has no exploitable meaning on its own. The original value is stored in a separate, controlled token vault, and only systems authorised to query the vault can map a token back to the real data. Vaultless schemes also exist, but the vault model is the usual one.
Tokenisation is commonly confused with encryption. Ciphertext is derived mathematically from the original and can be reversed by anyone holding the key; a vault-issued token has no such relationship and can only be mapped back through the vault. It also differs from data masking, which hides all or part of a value, often irreversibly, and it is one way of achieving pseudonymisation in the GDPR sense. Its best-known use is reducing PCI DSS scope: systems that handle only tokens, and that are segmented from the vault and the real card numbers, may fall outside the cardholder data environment.
Exam relevance: a scenario is likely to describe a retailer or payment process that must reduce its exposure and audit scope while still using card data. Candidates are expected to recognise tokenisation, to explain why a token is of little use to an attacker without the vault, and to keep it separate from encryption and masking.