Skip to main content

💼 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.

  • ID: /frameworks/pci-dss-v4.0/03/06/01

Description

That include:

  • Access to keys is restricted to the fewest number of custodians necessary.
  • Key-encrypting keys are at least as strong as the data-encrypting keys they protect.
  • Key-encrypting keys are stored separately from data-encrypting keys.
  • Keys are stored securely in the fewest possible locations and forms.

Similar

  • Sections
    • /frameworks/pci-dss-v3.2.1/03/05
    • /frameworks/pci-dss-v4.0.1/03/06/01
  • Internal
    • ID: dec-c-c138f39e

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 3.5 Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse.41no data
💼 PCI DSS v4.0.1 → 💼 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.31no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 3.5 Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse.41no data
💼 PCI DSS v4.0.1 → 💼 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse.31no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 3.6.1.1 A documented description of the cryptographic architecture is maintained.no data
💼 3.6.1.2 Secret and private keys used to encrypt/decrypt stored account data are stored in one (or more) of the described forms at all times.no data
💼 3.6.1.3 Access to cleartext cryptographic key components is restricted to the fewest number of custodians necessary.no data

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ Google Project with KMS keys has a principal with Owner role🟢1🟢 x6no data