# PCI PIN Security Requirements v3.1

Framework id: `pci_hsm`. Payment Security. Publisher: PCI Security Standards Council. Version: 3.1. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.pcisecuritystandards.org/document_library/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (10, average coverage 74%)
- 1 PIN Security Management: PL-01, PL-02, AC-01, AC-05, AC-06, PS-01, PS-02, PS-06, PM-01, PM-02 (80%)
- 2 PIN Entry Devices: PE-03, CM-08, SR-09, SR-10, SR-11, SA-04 (55%)
- 3 PIN Transmission: SC-08, SC-12, SC-13, SC-23, AC-04, AC-17 (72%)
- 4 PIN Processing: SC-12, SC-13, CM-03, CM-05, AC-03, AC-06 (60%)
- 5 Key Management: SC-12, SC-13, AC-05, AC-06, PS-06, CM-03, MP-04, MP-06 (85%)
- 6 Key Loading: PE-03, PE-02, PE-06, AC-05, PS-06, PS-07, SC-12, AU-02, AU-12 (65%)
- 7 HSM Physical Security: PE-01, PE-03, PE-04, PE-05, PE-06, PE-09, PE-13, PE-15, PE-18, SR-09 (82%)
- 8 HSM Logical Security: CM-02, CM-03, CM-06, SI-07, AC-03, AC-06, AU-02, AU-03, AU-06, AU-12 (78%)
- 9 Certificate and Asymmetric Key Management: SC-12, SC-13, SC-17, IA-05, IA-08, CM-03 (80%)
- 10 Audit and Compliance: CA-02, CA-05, CA-07, AU-01, AU-06, AU-11, IR-01, IR-04, IR-06, PM-06 (83%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=pci_hsm
- Control-to-clause mappings as JSON: /api/v1/frameworks/pci_hsm?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/pci-hsm.json
- Page for people: /frameworks/pci-hsm/
