PCI PIN Security
PCI PIN Transaction Security for payment terminals
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (14)
Access Control
| Code | Title |
|---|---|
| CO-17 | Access to Secret and Private Cryptographic Keys and Key Material Is Restricted |
Device Approval
| Code | Title |
|---|---|
| CO-1 | PINs Used for Cardholder Authentication Are Processed in Approved Devices |
| CO-2 | Devices Approved Under PCI PTS POI Have SRED Functionality |
Equipment Management
| Code | Title |
|---|---|
| CO-10 | Equipment Used to Process PINs and Keys Is Managed in a Secure Manner |
Key Distribution
| Code | Title |
|---|---|
| CO-Annex-A | Symmetric Key Distribution Using Asymmetric Techniques |
Key Injection
| Code | Title |
|---|---|
| CO-Annex-B | Key-Injection Facility Requirements |
Key Management
| Code | Title |
|---|---|
| CO-11 | Secret and Private Keys and Key Components Are Generated, Conveyed, and Used in a Manner That Prevents or Detects Their Unauthorized Disclosure, Modification, or Substitution |
| CO-12 | Keys Are Used in a Manner That Prevents or Detects Their Unauthorized Usage |
| CO-13 | Keys Are Administered Throughout Their Lifecycle in a Secure Manner |
| CO-14 | Materials Used to Generate or Transport Keys Are Treated With the Same Security as the Keys They Protect |
| CO-15 | Cryptographic Keys Are Replaced With New Keys When Knowledge of Or Access to a Key Is No Longer Required |
| CO-16 | Keys No Longer Used or Replaced Are Securely Destroyed |
| CO-5 | Cryptographic Keys Are Generated Using Approved Methods |
| CO-6 | Cryptographic Keys Are Conveyed or Transmitted Securely |
| CO-7 | Key Loading Is Handled in a Secure Manner |
| CO-8 | Keys Are Used Only for Their Designated Purpose |
| CO-9 | Keys Are Administered in a Secure Manner |
Logging and Monitoring
| Code | Title |
|---|---|
| CO-18 | Logging Is in Place to Enable Audit and Investigation of Key Management Activities |
PCI PIN Security: Cybersecurity Controls
Technical cybersecurity measures (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-06 | Network security and segmentation |
| PCI-PIN-07 | Endpoint protection and detection |
| PCI-PIN-08 | Application security controls |
| PCI-PIN-09 | Encryption and key management |
| PCI-PIN-10 | Secure configuration standards |
PCI PIN Security: Incident Management & Reporting
Incident handling for financial services (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-21 | Incident detection and classification |
| PCI-PIN-22 | Incident response and containment |
| PCI-PIN-23 | Regulatory reporting requirements |
| PCI-PIN-24 | Customer notification procedures |
| PCI-PIN-25 | Post-incident review and improvement |
PCI PIN Security: Information Security Governance
IT governance for financial institutions (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-04 | Security policy framework |
| PCI-PIN-05 | Roles and responsibilities definition |
PCI PIN Security: Operational Resilience
Business continuity and resilience (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-11 | Business continuity planning and testing |
| PCI-PIN-12 | Disaster recovery procedures |
| PCI-PIN-13 | Third-party dependency management |
| PCI-PIN-14 | Critical service identification |
| PCI-PIN-15 | Communication and escalation procedures |
PCI PIN Security: Third-Party Risk Management
Managing vendor and supplier risks (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-16 | Due diligence and onboarding |
| PCI-PIN-17 | Contractual security requirements |
| PCI-PIN-18 | Ongoing monitoring and assessment |
| PCI-PIN-19 | Concentration risk management |
| PCI-PIN-20 | Exit strategy and transition planning |
Physical Security
| Code | Title |
|---|---|
| CO-3 | POIs and HSMs Are Protected From Unauthorized Access |
| CO-4 | Procedures Exist to Protect Devices From Tampering and Substitution |
Risk Management
| Code | Title |
|---|---|
| CO-19 | Organizations Implement and Document Risk-Mitigation Practices |
Your Compliance Coverage
If you comply with PCI PIN Security, you already cover:
GLBA
40%
17 controls mapped
Compare →PCI P2PE
40%
17 controls mapped
Compare →OSFI B-13
40%
17 controls mapped
Compare →+ 431 more: FFIEC IT Examination Handbook (40%), Monetary Authority of Singapore Technology Risk Management Guidelines (40%)
See all 434 mapped frameworks ↓Maps to 434 other frameworks
Frequently Asked Questions
What is PCI PIN Security?
PCI PIN Security is a compliance framework from International with 14 domains and 43 controls. PCI PIN Transaction Security for payment terminals It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does PCI PIN Security have?
PCI PIN Security has 43 controls organised across 14 domains. The largest domains are Key Management (11 controls), PCI PIN Security: Cybersecurity Controls (5 controls), PCI PIN Security: Incident Management & Reporting (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does PCI PIN Security map to?
PCI PIN Security maps to 434 other compliance frameworks. The top mapping partners are GLBA (40% coverage), PCI P2PE (40% coverage), OSFI B-13 (40% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with PCI PIN Security compliance?
Start your PCI PIN Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI PIN Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required