Skip to main content

πŸ’Ό 3.4.1 If disk encryption is used, logical access must be managed separately and independently of native operating system authentication and access control mechanisms.

  • Contextual name: πŸ’Ό 3.4.1 If disk encryption is used, logical access must be managed separately and independently of native operating system authentication and access control mechanisms.

  • ID: /frameworks/pci-dss-v3.2.1/03/04/01

  • Located in: πŸ’Ό 3.4 Render PAN unreadable anywhere it is stored.

Description​

Decryption keys must not be associated with user accounts.

This requirement applies in addition to all other PCI DSS encryption and key-management requirements.

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/03/05/01/03
  • Internal
    • ID: dec-c-fe88d76c

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 3.5.1.3 If disk-level or partition-level encryption is used (rather than file-, column-, or field--level database encryption) to render PAN unreadable.7

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 3.5.1.3 If disk-level or partition-level encryption is used (rather than file-, column-, or field--level database encryption) to render PAN unreadable.7

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (7)​

PolicyLogic CountFlags
πŸ“ AWS Account EBS Volume Encryption Attribute is not enabled in all regions 🟒1🟒 x6
πŸ“ AWS EFS File System encryption is not enabled 🟒1🟒 x6
πŸ“ AWS RDS Instance Encryption is not enabled 🟒1🟒 x6
πŸ“ Azure Diagnostic Setting Logs export to Storage Account not encrypted with Customer-managed key 🟒1🟒 x6
πŸ“ Azure Storage Account With Critical Data is not encrypted with customer managed key 🟒🟒 x3
πŸ“ Azure Virtual Machine OS and Data disks are not encrypted with Customer-managed key 🟒1🟒 x6
πŸ“ Unattached Azure Managed Disk is not encrypted with Customer-managed key 🟒1🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-0bdcd2761
βœ‰οΈ dec-x-5c3c20671
βœ‰οΈ dec-x-6ba5ecd21
βœ‰οΈ dec-x-9cdb74071
βœ‰οΈ dec-x-966d31831
βœ‰οΈ dec-x-aef11ebd1
βœ‰οΈ dec-x-f63fd4f01