PCI DSS 4.0 3.6.1: 3.6.1 Procedures protect keys against disclosure and misuse
The entity defines and carries out procedures to shield the keys securing stored account data against misuse and disclosure, covering: (1) key access limited to the smallest number of custodians needed; (2) no key-encrypting key is weaker than any data-encrypting key it wraps; (3) key-encrypting keys kept apart from data-encrypting keys; and (4) keys held securely in as few locations and forms as possible. Applicability: covers keys protecting stored account data and key-encrypting keys that protect data-encrypting keys; both kinds need protection, and key-encrypting keys need especially strong measures because one may unlock many data-encrypting keys. Guidance recommends a centralized, standards-based key management system. Objective under the customized approach: processes guarding stored-data keys against misuse and disclosure are defined and running.
This control maps to 43 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 3.6.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.