PCI PIN Security
Key Management

PCI PIN Security CO-15: Cryptographic Keys Are Replaced With New Keys When Knowledge of Or Access to a Key Is No Longer Required

Cryptographic keys must be replaced when there is suspected or known compromise, when custodians leave their roles, or when the cryptoperiod expires. Replacement must use approved methods.

Maintained by Gerard BlokdykControl text last updated

Other controls in Key Management

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.