Куда я попал?
PCI PIN Security v3.1
Framework
В П.13-9
Для проведения оценки соответствия по документу войдите в систему.
Список требований
-
PIN Security Requirements:
13-9.1 PCs and similar devices must be:- Standalone (i.e., without modems, not connected to a LAN or WAN, not capable of wireless connections, etc.);
- Dedicated to only the key-loading function (e.g., there must not be any other application software installed); and
- Located in a physically secure room meeting the criteria of Requirement 32-9 that is dedicated to key-loading activities.
Testing Procedures:
13-9.1 For facilities using PC-based key-loading software platforms or similar devices, verify through interviews and observation that the platform is:- Standalone
- Dedicated to only key loading
- Located in a physically secure room meeting the criteria of Requirement 32-9 that is dedicated to key loading activities
-
PIN Security Requirements:
13-9.2 All hardware used in key loading (including the PC) must be managed under dual control. Key-injection must not occur unless there are minimally two individuals in the key-injection room at all times during the process. If a situation arises that would cause only one person to be in the room, all individuals must exit until at least two can be inside.
Testing Procedures:
13-9.2 Verify through interviews and observation that:- All hardware used in key loading (including the PC) is managed under dual control.
- Key-injection cannot occur unless there are minimally two individuals in the key-injection room at all times during the process.
- Mechanisms exist (See Requirement 32) that do not permit the room to be occupied by fewer than two authorized individuals.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.