PCI 3DS Core Security Standard
Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard

PCI 3DS Core Security Standard P2-6.2.5: P2-6.2.5 Non-console activity meets all other HSM and key rules

At the ACS and DS, anything done through non-console access still complies with every other HSM and key-management requirement. (Under Technical FAQ Q3's alternative, key components and shares loaded through a non-console interface are encrypted under a key-encryption key dedicated to key transport; the secure channel's own encryption does not count.) The assessor examines policies and procedures, interviews personnel, examines HSM configurations and observes connection processes.

Maintained by Gerard Blokdyk

Other controls in Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.