PCI DSS 3.6.1.3: Access to cleartext cryptographic key components is restricted to the fewest number
PCI DSS v4.0.1 control 3.6.1.3: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 3.6.
Requirement 3: Protect Stored Account Data › Section 3.6
Access to cleartext cryptographic key components is restricted to the fewest number of custodians necessary.
Summary
As few people as possible can see a cleartext key component.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 3.6.1.3 | Examine user access lists to verify that access to cleartext cryptographic key components is restricted to the fewest number of custodians necessary. |
Short, and it is the quantitative half of the custodian arrangement the rest of section 3.7 builds on. Fewest number necessary is a judgement you have to be able to defend, and the procedure examines user access lists, so it is answered by who can actually reach the components rather than by who is nominated. It connects to three other controls and is easiest to satisfy alongside them: 3.7.6 requires split knowledge and dual control where cleartext components are handled, 3.7.8 requires each custodian to acknowledge the role in writing, and 3.6.1.4 limits the locations rather than the people. The number that satisfies "fewest necessary" is therefore constrained from below: dual control means at least two.
What to prepare
- The custodian list, reconciled with the acknowledgements in 3.7.8.
- Access lists for wherever cleartext components exist, which is what the procedure examines.
- The reasoning for the number, given the dual-control requirement.
- Evidence of removal when a custodian changes role.
How to implement it
1. Work from the access list, not the nominated list. The two diverge, and the procedure examines the first.
2. Aim for the smallest number that still supports dual control and cover. Two is the floor and one is not an option.
3. Remove access on role change, not only on departure. A former custodian who still has access is still a custodian for this control.
4. Keep one register serving 3.6.1.3, 3.7.5, 3.7.6 and 3.7.8. All four depend on knowing who the custodians are.
Where this commonly fails
- An access list longer than the custodian list, usually through group membership.
- Administrators with incidental access to the key store, uncounted.
- Former custodians retaining access after a role change.
- A number chosen for convenience with no reasoning recorded.
Related controls
Others in section 3.6:
| Control | What it requires |
|---|---|
| 3.6.1 | Procedures are defined and implemented to protect cryptographic keys used to protect stored… |
| 3.6.1.1 | Service providers: A documented description of the cryptographic architecture is maintained… |
| 3.6.1.2 | Secret and private keys used to protect stored account data are stored in one (or more)… |
| 3.6.1.4 | Cryptographic keys are stored in the fewest possible locations |
← 3.6.1.2 · All controls · 3.6.1.4 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.