Reading a Cryptographic Inventory: A Field Guide for Assessors Evaluating Evidence under PCI DSS Requirement 12.3.3
Version 0.2. A field guide for assessors and compliance practitioners evaluating cryptographic inventory artifacts as evidence under PCI DSS Requirement 12.3.3. The guide separates two claims carried by an inventory: the first-order claim that a set of cryptographic assets exists in an environment, and the second-order claim that a stated method, applied to a stated scope at a stated time, reached a stated boundary. It argues that the second — the coverage declaration — is the only part of the package an assessor can evaluate without independently enumerating the estate, and that an inventory submitted without one is unfalsifiable at the point of assessment. Sections cover a three-part residual taxonomy (catalog, detection, temporal), a six-item triage of an inventory's face, six questions that surface a method's boundary, the interaction between discovery scope and cardholder data environment scope, and a specification of what a sufficient inventory states. Working paper. Not peer reviewed. The author is not a QSA and the document is not an interpretation of PCI DSS. It contains no engagement data and has not been empirically validated. Version 0.2 supersedes an uncirculated version 0.1; the revision is confined to Section Two. Author affiliation and declared interest are stated in the back matter.
Authors
- Simel E. Jenkins Bey (ORCID: https://orcid.org/0009-0009-2064-8078)
Institutions
- International Franchise Association (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-11
- DOI
- https://doi.org/10.5281/zenodo.22710008
- Primary Topic
- Digital and Cyber Forensics
- Type
- article
- Field-Weighted Citation Impact
- 0.00