This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC).
Key management mechanisms associated with these processes are beyond the scope of this document.
BSI recommends this version of standard for organisations operating in or with the UK. The ISO edition is available here if required.