unified

UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle

Cryptographic keys are generated, distributed, stored, used, rotated, revoked, and destroyed under documented procedures, with keys held in HSMs or hardened key stores and access limited to authorized custodians under dual control and split knowledge where warranted. Public key certificates are issued from approved certificate authorities, inventoried, monitored for expiry, renewed before lapse, and revoked promptly on compromise. Key-management activities are logged and periodically audited.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Cryptography & Key Management
type
preventive
category
technical

Details

unified_id
UC-CRYPTO-03
title
Manage cryptographic keys and certificates across their lifecycle
statement
Cryptographic keys are generated, distributed, stored, used, rotated, revoked, and destroyed under documented procedures, with keys held in HSMs or hardened key stores and access limited to authorized custodians under dual control and split knowledge where warranted. Public key certificates are issued from approved certificate authorities, inventoried, monitored for expiry, renewed before lapse, and revoked promptly on compromise. Key-management activities are logged and periodically audited.
domain
Cryptography & Key Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    SC-12
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SC-17
    coverage
    partial
    delta
    restricting managed trust stores to organization-approved trust anchors only
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections