PCI DSS 12.3.3: Cryptographic cipher suites and protocols in use are documented and reviewed at least once

PCI DSS v4.0.1 control 12.3.3: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.3.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.3

Cryptographic cipher suites and protocols in use are documented and reviewed at least once every 12 months, including at least the following:

  • An up-to-date inventory of all cryptographic cipher suites and protocols in use, including purpose and where used.
  • Active monitoring of industry trends regarding continued viability of all cryptographic cipher suites and protocols in use.
  • Documentation of a plan, to respond to anticipated changes in cryptographic vulnerabilities.

Summary

Keep an inventory of the cipher suites and protocols you use, watch whether they are still sound, and have a plan for when one is not.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.3.3 Examine documentation for cryptographic suites and protocols in use and interview personnel to verify the documentation and review is in accordance with all elements specified in this requirement.

The cryptographic agility control, and the third element is the forward-looking one entities rarely have: a plan to respond to anticipated changes in cryptographic vulnerabilities. The first two are an up-to-date inventory of all cryptographic cipher suites and protocols in use, including purpose and where used, and active monitoring of industry trends regarding continued viability. Together they answer a question that becomes urgent suddenly: when an algorithm is deprecated or broken, how quickly can you find everywhere it is used and replace it? An entity without the inventory answers that with a project. Note the relationship to 12.3.4, which reviews hardware and software technologies on the same annual cycle, and to 3.6.1.1, where service providers already maintain algorithm and key detail.

What to prepare

  • The inventory: each cipher suite and protocol, its purpose, and where it is used.
  • Evidence of monitoring industry trends, with dates.
  • The documented response plan.
  • The annual review record.

How to implement it

1. Build the inventory from configuration, not from memory. TLS configurations, database encryption settings, signing and hashing in applications, and VPN and SSH suites are the usual sources, and scanning for them is more reliable than asking.

2. Record where used, not just what. The value of the inventory is answering how much work a deprecation creates, and that needs locations.

3. Make the monitoring somebody's task. Industry trend monitoring with no owner does not happen, and it is the element with no natural trigger.

4. Write the plan before you need it. It does not have to be long: how a deprecated suite is identified, prioritised, replaced and verified is enough, and it is much harder to write during an incident.

Where this commonly fails

  • An inventory of algorithms with no record of where each is used.
  • No response plan, since the first two elements feel like the whole control.
  • Monitoring assumed to happen because engineers read the news.
  • The inventory built once and never updated as systems change.

Others in section 12.3:

Control What it requires
12.3.1 For each PCI DSS requirement that specifies completion of a targeted risk analysis…
12.3.2 A targeted risk analysis is performed for each PCI DSS requirement that the entity meets…
12.3.4 Hardware and software technologies in use are reviewed at least once every 12 months…

12.3.2 · All controls · 12.3.4

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.