Skip to main content
PCI DSS 2015 SIG Proposal: Securing Cryptographic Keys and Digital Certificates

PCI DSS 2015 SIG Proposal: Securing Cryptographic Keys and Digital Certificates

68 signatures 32 to reach 100
B
Bryan D. signed
A
Aditya T. signed
G
Gordon H. signed
S
Someone signed
S
Someone signed
C
Carl S. signed
S
Someone signed
J
Joseph P. signed
J
Justin H. signed
S
Someone signed
V,
Started by Venafi , Inc. 12 years ago

Why is securing keys and certificates an important PCI DSS special interest group (SIG) now? Cybercriminals are using keys and certificates to gain trusted status, be authenticated, and evade detection, bypassing other security controls and keeping their actions cloaked. And keys and certificates that protect payment card information are a particularly attractive target.


Vote for this SIG for guidance on use cases such as detecting, preventing, and remediating exploits of vulnerabilities such as Heartbleed and APTs designed to circumvent and misuse keys and certificates. If not secured, keys and certificates become a weak point in protecting payments systems and even undermine other critical security controls in place.


With the right guidance, you can simplify and ensure repeated audit success while continually defending against these trust-based attacks—and avoid being in the headlines with the next breach.


View the proposal on SlideShare at http://www.slideshare.net/Venafi/pci-scc-2015-sig-proposal-securing-keys-and-certificates.


Watch the on-demand webinar with SecurityMetrics at https://www.infosecurity-magazine.com/webinars/get-ready-for-pci-dss-v3/


Vote for the PCI SIG Cryptographic Keys and Digital Certificate Security Guidelines and get involved! Show your support by signing this petition, but then also make sure to vote between October 13-23 on the PCI SSC website. [https://www.pcisecuritystandards.org/]

Updates

October 1, 2014

The momentum behind this proposal proves that the industry is finally waking up to the massive security gaps in our current infrastructure. It is time for the PCI SCC to stop ignoring the blatant misuse of keys and certificates by criminals who exploit our silence.

17 Comments

B
Bryan Douglas
11 years ago Featured

keys and certs are integral to the safety of the internet, security infrastructures and PCI.

G
Gordon Hutton
11 years ago Featured

If the foundations you built your house on was full of holes you would fix them...this should be a P1 for every company.

D
Dean Glover
11 years ago Featured

This is critical and much over due. PKI weaknesses are never crypto related, it is always somewhere else within the trust model.

P
Phil Biegler
11 years ago Featured

Time to address a vulnerability that has been increasing risk for merchants everywhere.

B
Bill
11 years ago Featured

I am at a loss on why this even needs to be voted on. The PKI world/Talent is small and requires guidance.

M
Mike Hardy
11 years ago Featured

managing cert lifecycles is a nightmare for most teams and this stuff is getting ignored way too often. about time to get some real standards on this.

A
Anonymous
11 years ago

a must!

B
Bill Hohle
11 years ago

Key security is fundamental to use of PKI. Without it everyone is vulnerable.

Help this petition grow

Share it with friends to help reach 100 signatures.

Your share link

Share directly