PIN Security Requirements:
6-3 Printed key components must be printed within blind mailers or sealed in tamper-evident and authenticable packaging immediately after printing or transcription to ensure that:
- Only approved key custodians can observe the key component.
- Tampering can be visually detected.
Printers used for this purpose must not be used for other purposes, must not be networked (i.e., locally connected only), and must be managed under dual control. Location must be a secure room that meets the following requirements:
Testing Procedures:
6-3.a Examine documented procedures for printed key components and verify that they require printed key components to be printed within blind mailers or sealed in tamperevident and authenticable packaging immediately after printing such that:
- Only approved key custodians can observe the key component.
- Tampering can be detected.
6-3.b Observe blind mailers, tamper-evident and authenticable packaging, or other sealed containers used for key components to verify that components cannot be read from within and that tampering can be detected.
6-3.c Observe processes for printing key components to verify that:
- Key components are printed within blind mailers or sealed in tamper-evident and authenticable packaging immediately after printing, such that no one but the authorized custodian ever has physical access to the output;
- Printers are not networked; and
- Printers used for this purpose are not used for other purposes and are used only under dual control.