Skip to main content

πŸ’Ό 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.

Description​

That include:

  • Access to keys is restricted to the fewest number of custodians necessary.
  • Key-encrypting keys are at least as strong as the data-encrypting keys they protect.
  • Key-encrypting keys are stored separately from data-encrypting keys.
  • Keys are stored securely in the fewest possible locations and forms.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/03/05
    • /frameworks/pci-dss-v4.0.1/03/06/01

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 3.5 Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse.4
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.3

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 3.5 Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse.4
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.3

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 3.6.1.1 A documented description of the cryptographic architecture is maintained.
πŸ’Ό 3.6.1.2 Secret and private keys used to encrypt/decrypt stored account data are stored in one (or more) of the described forms at all times.
πŸ’Ό 3.6.1.3 Access to cleartext cryptographic key components is restricted to the fewest number of custodians necessary.