PIN Security Requirements:
9-2 Packaging or mailers (i.e., pre-numbered, tamper-evident packaging) containing clear-text key components are examined for evidence of tampering before being opened. Any sign of package tampering indicating a component was potentially compromised must be assessed and the analysis formally documented. If compromise is confirmed, and the result is that one person could have knowledge of the key, it must result in the destruction and replacement of:
- The set of components
- Any keys encrypted under this (combined) key
Testing Procedures:
9-2.a Verify documented procedures include requirements for all packaging or mailers containing clear-text key components to be examined for evidence of tampering before being opened.
9-2.b Interview responsible personnel and observe processes to verify that all packaging or mailers containing clear-text key components are examined for evidence of tampering before being opened.
9-2.c Verify documented procedures require that any sign of package tampering is identified, reported and if compromise is confirmed ultimately results in the destruction and replacement of both:
- The set of components
- Any keys encrypted under this (combined) key
9-2.d Interview responsible personnel and observe processes to verify that if a package shows signs of tampering indicating a component was potentially compromised, processes are implemented to identify the tampering, report/escalate it, and ,if compromise is confirmed, ultimately results in the destruction and replacement of both:
- The set of components
- Any keys encrypted under this (combined) key.
9-2.e Examine records related to any escalated transmittal event. Verify that if compromise is confirmed it resulted in the destruction and replacement of both:
- The set of components
- Any keys encrypted under this (combined) key