Requirement 3 · Protect stored account data

3.7 Key management is fully documented and implemented

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL3.7 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Define key generation, distribution, rotation, retirement and replacement procedures.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 3.7, in plain English.

3.7.1Key-management procedures cover generation of strong cryptographic keys.
3.7.2Key-management procedures cover secure distribution of keys.
3.7.3Key-management procedures cover secure storage of keys.
3.7.4Keys are changed at the end of a defined cryptoperiod.
3.7.5Keys are retired, replaced, or destroyed on cryptoperiod end or compromise, and retired keys are not reused.
3.7.6Manual cleartext key operations use split knowledge and dual control.
3.7.7Unauthorized substitution of keys is prevented.
3.7.8Key custodians formally acknowledge their responsibilities.
3.7.9Service providers document and give customers guidance on securely handling shared keys.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 3, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.