Skip to main content

๐Ÿ’ผ 3.5 Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse.

  • Contextual name: ๐Ÿ’ผ 3.5 Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse.

  • ID: /frameworks/pci-dss-v3.2.1/03/05

  • Located in: ๐Ÿ’ผ 3 Protect stored cardholder data

Descriptionโ€‹

This requirement applies to keys used to encrypt stored cardholder data, and also applies to key-encrypting keys used to protect data-encrypting keysโ€”such key-encrypting keys must be at least as strong as the data-encrypting key.

Similarโ€‹

  • Sections
    • /frameworks/pci-dss-v4.0/03/06/01
  • Internal
    • ID: dec-c-04657187

Similar Sections (Take Policies From)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ PCI DSS v4.0 โ†’ ๐Ÿ’ผ 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.3

Similar Sections (Give Policies To)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ PCI DSS v4.0 โ†’ ๐Ÿ’ผ 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.3

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 3.5.1 Maintain a documented description of the cryptographic architecture
๐Ÿ’ผ 3.5.2 Restrict access to cryptographic keys to the fewest number of custodians necessary.
๐Ÿ’ผ 3.5.3 Store secret and private keys used to encrypt/decrypt cardholder data in one (or more) of the described forms at all times.
๐Ÿ’ผ 3.5.4 Store cryptographic keys in the fewest possible locations.