Skip to main content

πŸ’Ό 3.7.4 Key management policies and procedures are implemented for cryptographic key changes for keys that have reached the end of their cryptoperiod.

Description​

As defined by the associated application vendor or key owner, and based on industry best practices and guidelines.

Include the following:

  • A defined cryptoperiod for each key type in use.
  • A process for key changes at the end of the defined cryptoperiod.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/03/06/04
    • /frameworks/pci-dss-v4.0.1/03/07/04

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 3.6.4 Cryptographic key changes for keys that have reached the end of their cryptoperiod, as defined by the associated application vendor or key owner, and based on industry best practices and guidelines.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 3.7.4 Key management policies and procedures are implemented for cryptographic key changes for keys that have reached the end of their cryptoperiod.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 3.6.4 Cryptographic key changes for keys that have reached the end of their cryptoperiod, as defined by the associated application vendor or key owner, and based on industry best practices and guidelines.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 3.7.4 Key management policies and procedures are implemented for cryptographic key changes for keys that have reached the end of their cryptoperiod.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags