3.7 Key management is fully documented and implemented
How to meet it
Define key generation, distribution, rotation, retirement and replacement procedures.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 3.7, in plain English.
3.7.1Key-management procedures cover generation of strong cryptographic keys.
3.7.2Key-management procedures cover secure distribution of keys.
3.7.3Key-management procedures cover secure storage of keys.
3.7.4Keys are changed at the end of a defined cryptoperiod.
3.7.5Keys are retired, replaced, or destroyed on cryptoperiod end or compromise, and retired keys are not reused.
3.7.6Manual cleartext key operations use split knowledge and dual control.
3.7.7Unauthorized substitution of keys is prevented.
3.7.8Key custodians formally acknowledge their responsibilities.
3.7.9Service providers document and give customers guidance on securely handling shared keys.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Information security roles and responsibilitiesUse for ISO 27001 A.5.2, A.5.3 and A.5.4, defining security roles, segregation of duties, management responsibilities, and SOC 2 organisational controls.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Cryptography and key management policyUse for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.
Open the control-to-policy mapBack to Requirement 3, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.