simpl.
Cybersecurity GRC 14 items

HSM & Key Ceremony Review

Reviews hardware security module operations and key ceremony procedures covering HSM security, ceremony controls, key lifecycle, and audit evidence.

NIST 800-57FIPS 140-3PCI PIN

Free PDF · enter your email to download.

HSM Security

  • Is the HSM validated to FIPS 140-2/3 at the required level for its use? *
  • Is HSM firmware kept current and authenticated before installation? *
  • Is administrative access to the HSM restricted, logged, and role-separated? *
  • Is tamper response/zeroization configured and tested? *

Key Ceremony Controls

  • Is a documented, scripted ceremony procedure followed and approved in advance? *
  • Is dual control and split knowledge enforced for key component custodians? *
  • Are ceremony participants, roles, and independent witnesses identified and verified? *
  • Is the ceremony conducted in a secure, access-controlled environment? *

Key Lifecycle

  • Are keys generated within the HSM using an approved random source? *
  • Are key backup, recovery, rotation, and destruction procedures documented and tested? *
  • Are cryptographic keys segregated by purpose and environment? *

Audit & Evidence

  • Is a signed ceremony log/attestation retained with all participant signatures? *
  • Are HSM logs retained and reviewed for unauthorized operations? *
  • Is video or independent observation retained for high-assurance ceremonies?

Download the full HSM & Key Ceremony Review checklist

Get it as a clean, printable PDF — free.