Diff: FAQ #1084
For PCI DSS requirement 3.4.1 for disk encryption, what is the intent of requiring that logical access must be managed independently of native operating access control mechanisms?
Earlier Version
2008-02-24 00:00:00 UTC
2008-02-24 00:00:00 UTC
Later Version
2014-05-28 15:06:00 UTC
2014-05-28 15:06:00 UTC
Removed
Added
The intent of this requirement is to address the acceptability of disk encryption for rendering cardholder data unreadable. Disk encryption encrypts data stored on a computer’s mass storage and automatically decrypts the information when an authorized user requests it. Disk-encryption systems intercept operating system read and write operations and carry out the appropriate cryptographic transformations without any special action by the user other than supplying a password or pass phrase at the beginning of a session. Based on these characteristics of disk encryption, to be compliant with this requirement, the disk-encryption method cannot have:
A direct association1. Use the same user account authenticator as the operating system, or
2. Use a decryption key that is associated withthe operating system, or
Decryptionor derived from the system’s local user account database or general networkeys associated with user account login credentials.
2. Use a decryption key that is associated with
Decryption