Skip to main content

πŸ’Ό 3.5.1 Maintain a documented description of the cryptographic architecture

Description​

Additional requirement for service providers only.

That includes:

  • Details of all algorithms, protocols, and keys used for the protection of cardholder data, including key strength and expiry date
  • Description of the key usage for each key
  • Inventory of any HSMs and other SCDs used for key management.

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/03/06/01/01
  • Internal
    • ID: dec-c-925cde17

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 3.6.1.1 A documented description of the cryptographic architecture is maintained.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 3.6.1.1 A documented description of the cryptographic architecture is maintained.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags