The code goes by different names depending on the network — CVC, CVV2, CVC2 and CID all describe the same idea. It is printed on the card rather than encoded in the magnetic stripe or chip, so a stolen card number alone will not produce it.
Critically, the code may never be stored after a transaction is authorised. PCI DSS forbids retaining it even in encrypted form, which is why a saved card on file still asks for the code on some purchases, and why recurring billing relies on tokenization instead.