Which statement about keys for stored cardholder data is true?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

Which statement about keys for stored cardholder data is true?

Explanation:
Key management for stored cardholder data requires formal, documented procedures and strong protection for all keys, including the key-encrypting keys (KEKs). This matters because the KEK protects the data-encryption keys (DEKs) that actually secure the CHD. If the KEK is weaker than the DEKs it protects, compromising the KEK could expose many DEKs and the data they safeguard. So, having documented, implemented procedures ensures consistent control over key generation, storage, access, rotation, and revocation, and it enforces the practice that KEKs are at least as strong as DEKs. The other statements fall short of these requirements. Keys must be documented and controlled, KEKs require protection and strength comparable to DEKs, and sharing keys across organizations is not permitted due to security and segregation concerns.

Key management for stored cardholder data requires formal, documented procedures and strong protection for all keys, including the key-encrypting keys (KEKs). This matters because the KEK protects the data-encryption keys (DEKs) that actually secure the CHD. If the KEK is weaker than the DEKs it protects, compromising the KEK could expose many DEKs and the data they safeguard. So, having documented, implemented procedures ensures consistent control over key generation, storage, access, rotation, and revocation, and it enforces the practice that KEKs are at least as strong as DEKs.

The other statements fall short of these requirements. Keys must be documented and controlled, KEKs require protection and strength comparable to DEKs, and sharing keys across organizations is not permitted due to security and segregation concerns.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy