PCI PIN Security
Normative Annex A2: Certification and registration authority operations – PCI PIN Security

PCI PIN Security A2:19-5: PCI PIN A2:19-5

A production CA or RA platform may be used for testing on a temporary basis only where a business rationale exists and only once every item of keying material has been removed from the HSMs and from the CA and RA servers. After testing, every test key is deleted, the platforms are wiped and rebuilt using read-only media, and the production keys are restored under dual control and split knowledge, with physical and logical security maintained the whole time.

Maintained by Gerard BlokdykControl text last updated

Other controls in Normative Annex A2: Certification and registration authority operations – PCI PIN Security

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.