Skip to main content

๐Ÿ’ผ 3.6 Fully document and implement all keymanagement processes and procedures

for cryptographic keys used for encryption of cardholder data.

  • Contextual name: ๐Ÿ’ผ 3.6 Fully document and implement all keymanagement processes and procedures for cryptographic keys used for encryption of cardholder data.
  • ID: /frameworks/pci-dss-v3.2.1/03/06
  • Located in: ๐Ÿ’ผ 3 Protect stored cardholder data

Descriptionโ€‹

Numerous industry standards for key management are available from various resources including NIST, which can be found at http://csrc.nist.gov

Similarโ€‹

  • Internal
    • ID: dec-c-e88e866b

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 3.6.1 Generation of strong cryptographic keys.
๐Ÿ’ผ 3.6.2 Secure cryptographic key distribution.
๐Ÿ’ผ 3.6.3 Secure cryptographic key storage.
๐Ÿ’ผ 3.6.4 Cryptographic key changes for keys that have reached the end of their cryptoperiod, as defined by the associated application vendor or key owner, and based on industry best practices and guidelines.
๐Ÿ’ผ 3.6.5 Retirement or replacement of keys as deemed necessary when the integrity of the key has been weakened, or keys are suspected of being compromised.
๐Ÿ’ผ 3.6.6 If manual clear-text cryptographic key-management operations are used, these operations must be managed using split knowledge and dual control.
๐Ÿ’ผ 3.6.7 Prevention of unauthorized substitution of cryptographic keys.
๐Ÿ’ผ 3.6.8 Requirement for cryptographic key custodians to formally acknowledge that they understand and accept their key-custodian responsibilities.