Reading a Cryptographic Inventory: A Field Guide for Assessors Evaluating Evidence under PCI DSS Requirement 12.3.3

Version 0.2. A field guide for assessors and compliance practitioners evaluating cryptographic inventory artifacts as evidence under PCI DSS Requirement 12.3.3. The guide separates two claims carried by an inventory: the first-order claim that a set of cryptographic assets exists in an environment, and the second-order claim that a stated method, applied to a stated scope at a stated time, reached a stated boundary. It argues that the second — the coverage declaration — is the only part of the package an assessor can evaluate without independently enumerating the estate, and that an inventory submitted without one is unfalsifiable at the point of assessment. Sections cover a three-part residual taxonomy (catalog, detection, temporal), a six-item triage of an inventory's face, six questions that surface a method's boundary, the interaction between discovery scope and cardholder data environment scope, and a specification of what a sufficient inventory states. Working paper. Not peer reviewed. The author is not a QSA and the document is not an interpretation of PCI DSS. It contains no engagement data and has not been empirically validated. Version 0.2 supersedes an uncirculated version 0.1; the revision is confined to Section Two. Author affiliation and declared interest are stated in the back matter.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-11
DOI
https://doi.org/10.5281/zenodo.22710008
Primary Topic
Digital and Cyber Forensics
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Reading a Cryptographic Inventory: A Field Guide for Assessors Evaluating Evidence under PCI DSS Requirement 12.3.3

Simel E. Jenkins Bey
Zenodo (CERN European Organization for Nuclear Research)
Digital and Cyber Forensics
article

Reading a Cryptographic Inventory: A Field Guide for Assessors Evaluating Evidence under PCI DSS Requirement 12.3.3

Simel E. Jenkins Bey
article en

Abstract

Version 0.2. A field guide for assessors and compliance practitioners evaluating cryptographic inventory artifacts as evidence under PCI DSS Requirement 12.3.3. The guide separates two claims carried by an inventory: the first-order claim that a set of cryptographic assets exists in an environment, and the second-order claim that a stated method, applied to a stated scope at a stated time, reached a stated boundary. It argues that the second — the coverage declaration — is the only part of the package an assessor can evaluate without independently enumerating the estate, and that an inventory submitted without one is unfalsifiable at the point of assessment. Sections cover a three-part residual taxonomy (catalog, detection, temporal), a six-item triage of an inventory's face, six questions that surface a method's boundary, the interaction between discovery scope and cardholder data environment scope, and a specification of what a sufficient inventory states. Working paper. Not peer reviewed. The author is not a QSA and the document is not an interpretation of PCI DSS. It contains no engagement data and has not been empirically validated. Version 0.2 supersedes an uncirculated version 0.1; the revision is confined to Section Two. Author affiliation and declared interest are stated in the back matter.

Zenodo (CERN European Organization for Nuclear Research)
International Franchise Association (US)
Openalex Percentile: Top 4%
Digital and Cyber Forensics
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Reading a Cryptographic Inventory: A Field Guide for Assessors Evaluating Evidence under PCI DSS Requirement 12.3.3 — Simel E. Jenkins Bey · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS