PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum  

Go Back   PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum > Payment Card Industry Data Security Standard Frequently Asked Questions (PCI DSS FAQ) > Protect Cardholder Data > [PCI-DSS] Requirement 3: Protect stored cardholder data

[PCI-DSS] Requirement 3: Protect stored cardholder data Encryption is a critical component of cardholder data protection. If an intruder circumvents other network security controls and gains access to encrypted data, without the proper cryptographic keys, the data is unreadable and unusable to that person. Other effective methods of protecting stored data should be considered as potential risk mitigation opportunities. For example, methods for minimizing risk include not storing cardholder data unless absolutely necessary, truncating cardholder data if full PAN is not needed, and not sending PAN in unencrypted e-mails.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-18-2007, 02:56 AM
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Jul 2002
Posts: 229
Default [PCI-DSS] 3.6.4 Periodic cryptographic key changes

3.6.4 Periodic cryptographic key changes
  • As deemed necessary and recommended by the associated application (for example, re-keying); preferably automatically
  • At least annually
3.6.4 Verify that key management procedures require periodic key changes. Verify that key change procedures are carried out at least annually
Reply With Quote
  #2  
Old 04-22-2009, 09:59 AM
randyb randyb is offline
Junior Member
 
Join Date: Apr 2009
Posts: 1
Default

I understand that PCI DSS requires encryption keys to be changed annually. Is it necessary to decrypt all of the old data and re-encrypt it with the new key, or is it sufficient just to discontinue the use of the old key for encryption. Only new keys would be used for encryption. Then, after all old data using the old key is retired/destroyed, the old key would be destroyed since it would no longer be required for decryption.

It seems to me that the purpose of the rekeying requirement is to prevent the use of a key for very long periods of time, which if compromised would provide an attacker access to historical, current, and future data. With the method I described, a very successful attacker may have access to portions of the data, but not all, or even most of it.

Thanks,
Randy
Reply With Quote
Reply

Bookmarks

Tags
cryptographic key changes, re-key, rekey
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[PCI-DSS] 3.6.2 Secure cryptographic key distribution admin [PCI-DSS] Requirement 3: Protect stored cardholder data 3 05-03-2010 08:32 AM
[PCI-DSS] 3.6.3 Secure cryptographic key storage admin [PCI-DSS] Requirement 3: Protect stored cardholder data 0 03-18-2007 02:56 AM
[PA-DSS] 2.7 Securely delete any cryptographic key material or cryptogram stored by previous versions of the payment application, in accordance with industry-accepted standards for secure deletion, as defined, for example the list of approved products maintained by the National Security Agency, or by other State or National standards or regulations. These are cryptographic keys used to encrypt or verify cardholder data admin [PA-DSS] 2. Protect stored cardholder data 0 03-18-2007 02:44 AM
[PA-DSS] 2.6 Payment application must implement key management processes and procedures for keys used for encryption of cardholder data admin [PA-DSS] 2. Protect stored cardholder data 0 03-18-2007 02:44 AM


All times are GMT -4. The time now is 04:32 AM.


All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest ©1997 - 2010 by PCIDSSFAQ.ORG, except where noted otherwise.
Powered by vBulletin, Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
PCI-DSS Forum  |  PA-DSS Forum