At the ACS and DS, personnel with logical access to HSMs either work at the HSM console or use a non-console access solution evaluated by an independent laboratory against the ISO 13491 sections the standard lists (Annex A A.2.2; Annex D D.2, with no single-DEA MACs; Annex E E.2.1 and E.2.2, with random number generators meeting SP 800-90A only; Annex F F.2.1 and F.2.2; and Annex G G.2.1 and G.2.2 where digital signatures are supported). Compensating controls are not accepted for this requirement. Technical FAQ Q3 (September 2023) adds an alternative that, if met in full, satisfies P2-6.2.1 to P2-6.2.5: MFA and a secure channel for non-console management; dual control and split knowledge for secret or private keys and components entering or leaving the HSM; clear-text components loaded only from an SCD validated at Level 3 under FIPS 140-3 or its predecessor 140-2, or PTS-approved; and components encrypted under a dedicated transport key, not only by the secure channel. The assessor examines system configurations and, for non-console access, evidence that the solution was validated, and observes it.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.