Why is key management critical for encryption in PCI DSS?
- A.Keys manage themselves, given that the standard permits account data to be sent over wireless without any encryption for SAQ A-EP merchants across every in-scope payment channel
- B.Only the algorithm matters, which the standard's glossary defines broadly enough that any reversible encoding, including Base64, qualifies as strong cryptography provided the encoding scheme is kept confidential
- C.Keys are not important, as tokenization and encryption are treated as equivalent controls by the standard for service providers whenever a qualified security assessor is engaged
- D.Without proper key management, encryption can be rendered useless; if keys are compromised, lost, or improperly handled, encrypted cardholder data may be exposed or inaccessible
Why D is correct
Encryption is only as strong as its key management. Compromised or mishandled keys can expose all protected cardholder data.
Know someone studying for PCI DSS? Send them this one.