Куда я попал?
PCI PIN Security v3.1
Framework
Requirement 21
Для проведения оценки соответствия по документу войдите в систему.
Список требований
-
PIN Security Requirements:
21-1 Secret or private keys must only exist in one or more of the following forms:- At least two separate key shares (secret or private) or full-length components (secret)
- Encrypted with a key of equal or greater strength as delineated in Annex C
- Contained within a secure cryptographic device
Note: Key-injection facilities may have clear-text keying material outside of a SCD when used within a secure room in accordance with Requirement 32 in Annex B.
Testing Procedures:
21-1.a Examine documented procedures for key storage and usage to verify that secret or private keys only exist in one or more approved forms at all times when stored.
21-1.b Observe key stores to verify that secret or private keys only exist in one or more approved forms at all times when stored. -
PIN Security Requirements:
21-3 Key components/shares must be stored as follows:
Testing Procedures:
21-3 Examine documented procedures, interview responsible personnel, and inspect key-component/share storage locations to verify that key components/shares are stored as outlined in Requirements 21-3.1 through 21- 3.3 below.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.