The PCI Security Standards Council has published the PCI Key Management and Operations (KMO) Standard v1.0 designed for securing the systems, processes and devices used to manage cryptographic keys protecting account data. The Standard covers the cryptographic key lifecycle, from generation through to secure disposal and all aspects of using keys in cryptographic protection of PCI defined payment assets. Foregenix reviewed the Standard and here are the most important things you should know about it.
PCI KMO covers the complete cryptographic key lifecycle, from generation and distribution through use, storage, compromise response, archival and destruction. Its initial focus is on consolidating, aligning and updating key management requirements associated with PCI PIN and PCI P2PE. Over time, it may also support additional PCI standards, programs and data types. However, initial version of the Standard covers PCI PIN and PCI P2PE.
The Standard is structured around four main Domains:
PCI SSC describes KMO as a modular, “assess-once-use-many” framework which will help to consolidate PCI PIN and PCI P2PE programs as a first step. Therefore, a validated PCI KMO service may be referenced by other PCI assessments where permitted, reducing repeated assessment of the same key management operations.
The Standard is particularly relevant to:
PCI SSC designed PCI KMO to cover the entire lifecycle of cryptographic keys for several PCI Standards and Programs. Starting with PIN and P2PE KMO soon may cover all cryptographic key management scenarios applicable to the organisation. By implementing PCI KMO, organisations currently maintaining both PCI PIN and PCI P2PE programs may avoid duplicated assessments and extend their PCI PIN certification validity from 24 to 36 months.
In addition to traditional key management lifecycle controls, PCI KMO addresses risks associated with remote and shared cryptographic environments, including cloud HSM Service Providers. KMO defines and regulates the HSM-as-a-Service operating model and cover all aspects of using it securely.
PCI KMO requires from cloud HSM Third-Party Service Providers:
This makes Key Injection Facilities, PIN Processing Services and other eligible for PCI PIN and PCI P2PE organisations rely on PCI KMO compliant Third-Party Service Providers and make sure the cloud HSM layer and secure tenant management were assessed against the defined security controls.
PCI KMO explicitly recognises services and cryptographic keys that were treated as supporting infrastructure rather than part of the main payment key management assessments. The secure key management requirements now explicitly cover software and firmware signing keys, HSM-administration and authentication keys, tenant provisioning keys. This makes sure all risk scenarios related to supporting keys will be covered during the assessment.
Based on our extensive experience assessing PCI Crypto Standards such as PCI P2PE, PIN, and 3DS. We are confident that we can provide the best support to help your organisation transition to the new KMO Standard.
Our QSA-certified team provides the technical guidance needed to secure your environment while minimising your compliance overhead.
Get in touch with us today.