Key Management System
Also: KMS
PCIComplianceHubLast updated
The combination of hardware and software that generates, distributes and manages cryptographic keys for the devices and applications that use them. It is where the key-management policies and procedures of Requirement 3.7 are carried out, whether it is an HSM with its control software or a cloud provider's managed key service.
Applies to. Any entity holding cryptographic keys that protect stored account data. Requirement 3.7 governs the procedures; the system is what performs them.
Example. An entity's payment application asks the key management system to encrypt a PAN; the data-encrypting key never leaves the system, and the key-encrypting key that protects it never leaves the HSM. Rotation at the end of the cryptoperiod (3.7.4) happens inside the system without the application changing.
Limits. A key management system is in scope by definition, and access to it is administrative access. It does not remove the documentary obligations: the entity still needs the key custodians' acknowledgements (3.7.8), the inventory of keys and their cryptoperiods, and the procedures for generation (3.7.1), distribution (3.7.2), storage (3.7.3), retirement (3.7.5) and, where cleartext components are handled, split knowledge and dual control (3.7.6). A cloud key service is a third-party service provider for these purposes.