PCI 3DS Core Security Standard
Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard

PCI 3DS Core Security Standard P2-6.2.1: P2-6.2.1 Logical HSM access at the console or through an evaluated solution

At the ACS and DS, personnel with logical access to HSMs either work at the HSM console or use a non-console access solution evaluated by an independent laboratory against the ISO 13491 sections the standard lists (Annex A A.2.2; Annex D D.2, with no single-DEA MACs; Annex E E.2.1 and E.2.2, with random number generators meeting SP 800-90A only; Annex F F.2.1 and F.2.2; and Annex G G.2.1 and G.2.2 where digital signatures are supported). Compensating controls are not accepted for this requirement. Technical FAQ Q3 (September 2023) adds an alternative that, if met in full, satisfies P2-6.2.1 to P2-6.2.5: MFA and a secure channel for non-console management; dual control and split knowledge for secret or private keys and components entering or leaving the HSM; clear-text components loaded only from an SCD validated at Level 3 under FIPS 140-3 or its predecessor 140-2, or PTS-approved; and components encrypted under a dedicated transport key, not only by the secure channel. The assessor examines system configurations and, for non-console access, evidence that the solution was validated, and observes it.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI PIN Security · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.