unified
UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle
Cryptographic keys are generated, distributed, stored, used, rotated, revoked, and destroyed under documented procedures, with keys held in HSMs or hardened key stores and access limited to authorized custodians under dual control and split knowledge where warranted. Public key certificates are issued from approved certificate authorities, inventoried, monitored for expiry, renewed before lapse, and revoked promptly on compromise. Key-management activities are logged and periodically audited.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Cryptography & Key Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CRYPTO-03
- title
- Manage cryptographic keys and certificates across their lifecycle
- statement
- Cryptographic keys are generated, distributed, stored, used, rotated, revoked, and destroyed under documented procedures, with keys held in HSMs or hardened key stores and access limited to authorized custodians under dual control and split knowledge where warranted. Public key certificates are issued from approved certificate authorities, inventoried, monitored for expiry, renewed before lapse, and revoked promptly on compromise. Key-management activities are logged and periodically audited.
- domain
- Cryptography & Key Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SC-12
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-17
- coverage
- partial
- delta
- restricting managed trust stores to organization-approved trust anchors only
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle maps_to SC-12 — Cryptographic Key Establishment and Management
- framework
- nist-800-53
- control_id
- SC-12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle mitigates Compromised or counterfeit certificates / certificate authority
- strength
- primary
- rationale
- Issues certificates only from approved CAs, inventories/monitors them, and revokes promptly on compromise, the direct first-order defense against compromised/counterfeit certificates.
- UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- related
- rationale
- Protecting private keys in HSMs and revoking compromised certs denies attackers the stolen-key/impersonation path used for eavesdropping and man-in-the-middle.
- UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle mitigates Weak or absent encryption and key management
- strength
- primary
- rationale
- Governs key generation, HSM storage, rotation, and destruction under dual control, directly remediating the poor-key-management facet that weakens encryption.
- Cryptographic Key Management Review operates UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle
- UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle maps_to SC-17 — Public Key Infrastructure Certificates
- framework
- nist-800-53
- control_id
- SC-17
- coverage
- partial
- delta
- restricting managed trust stores to organization-approved trust anchors only
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.