PCI PIN Security
Control Objective 5: Keys are used in a manner that prevents or detects their unauthorized usage – PCI PIN Security

PCI PIN Security 19-5: PCI PIN 19-5

A production HSM and its server may be used for testing on a temporary basis only where a business rationale exists and only once every item of keying material has been removed. After testing, every test key is deleted, the platform is wiped and rebuilt using read-only media, and the production keys are restored under dual control and split knowledge, with physical and logical security maintained the whole time.

Maintained by Gerard BlokdykControl text last updated

Other controls in Control Objective 5: Keys are used in a manner that prevents or detects their unauthorized usage – PCI PIN Security

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.