Cybersecurity GRC 14 items
HSM & Key Ceremony Review
Reviews hardware security module operations and key ceremony procedures covering HSM security, ceremony controls, key lifecycle, and audit evidence.
NIST 800-57FIPS 140-3PCI PIN
Free PDF · enter your email to download.
HSM Security
- Is the HSM validated to FIPS 140-2/3 at the required level for its use? *
- Is HSM firmware kept current and authenticated before installation? *
- Is administrative access to the HSM restricted, logged, and role-separated? *
- Is tamper response/zeroization configured and tested? *
Key Ceremony Controls
- Is a documented, scripted ceremony procedure followed and approved in advance? *
- Is dual control and split knowledge enforced for key component custodians? *
- Are ceremony participants, roles, and independent witnesses identified and verified? *
- Is the ceremony conducted in a secure, access-controlled environment? *
Key Lifecycle
- Are keys generated within the HSM using an approved random source? *
- Are key backup, recovery, rotation, and destruction procedures documented and tested? *
- Are cryptographic keys segregated by purpose and environment? *
Audit & Evidence
- Is a signed ceremony log/attestation retained with all participant signatures? *
- Are HSM logs retained and reviewed for unauthorized operations? *
- Is video or independent observation retained for high-assurance ceremonies?
Download the full HSM & Key Ceremony Review checklist
Get it as a clean, printable PDF — free.
