PIN Security Requirements:
25-1.4 In order for key custodians to be free from undue influence in discharging their custodial duties, key custodians sufficient to form the necessary threshold to create a key must not directly report to the same individual except as noted below for organizations of insufficient size.
For example, for a key managed as three components, at least two individuals report to different individuals. In an m-of-n scheme (which must use a recognized secret-sharing scheme such as Shamir), such as three of five key shares to form the key, key custodians sufficient to form the threshold necessary to form the key must not report to the same individual.
The components collectively held by an individual and his or her direct reports shall not constitute a quorum (or shall not provide any information about the value of the key that is not derivable from a single component).
Custodians must not become a custodian for a component/share of a key where the custodian has previously been or is currently a custodian for another component/share of that key if that would collectively constitute a quorum to form the actual key.
When the overall organization is of insufficient size such that the reporting structure cannot support this requirement, procedural controls can be implemented.
Organizations that are of insufficient size that they cannot support the reporting-structure requirement must:
- Ensure key custodians do not report to each other (i.e., the manager cannot also be a key custodian);
- Receive explicit training to instruct them from sharing key components with their direct manager;
- Sign key-custodian agreements that include an attestation to the requirement; and
- Receive training that includes procedures to report any violations.
Testing Procedures:
25-1.4.a Examine key-custodian assignments and organization charts to confirm the following:
- Key custodians that form the necessary threshold to create a key do not directly report to the same individual.
- Neither direct reports nor the direct reports in combination with their immediate supervisors possess the necessary threshold of key components sufficient to form any given key.
- Key custodians are not and have not been a custodian for another component/share of a key where that collectively would constitute a quorum to form the actual key.
25-1.4.b For organizations that are such a small, modest size that they cannot support the reporting-structure requirement, ensure that documented procedures exist and are followed to:
- Ensure key custodians do not report to each other.
- Receive explicit training to instruct them from sharing key components with their direct manager.
- Sign key-custodian agreement that includes an attestation to the requirement.
- Ensure training includes procedures to report any violations.