{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Cryptography & Key Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-03","description":"Cryptographic keys are generated, distributed, stored, used, rotated, revoked, and destroyed under documented procedures, with keys held in HSMs or hardened key stores and access limited to authorized custodians under dual control and split knowledge where warranted. Public key certificates are issued from approved certificate authorities, inventoried, monitored for expiry, renewed before lapse, and revoked promptly on compromise. Key-management activities are logged and periodically audited.","details":{"control_category":"technical","control_type":"preventive","domain":"Cryptography & Key Management","guidance":[],"members":[{"control_id":"SC-12","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-17","coverage":"partial","delta":"restricting managed trust stores to organization-approved trust anchors only","framework":"nist-800-53","relationship":"intersects_with"}],"statement":"Cryptographic keys are generated, distributed, stored, used, rotated, revoked, and destroyed under documented procedures, with keys held in HSMs or hardened key stores and access limited to authorized custodians under dual control and split knowledge where warranted. Public key certificates are issued from approved certificate authorities, inventoried, monitored for expiry, renewed before lapse, and revoked promptly on compromise. Key-management activities are logged and periodically audited.","title":"Manage cryptographic keys and certificates across their lifecycle","unified_id":"UC-CRYPTO-03"},"id":"uc:UC-CRYPTO-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-03","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:252a262b37fb5058b624267ecd2537c260e7b073842b0d39f443ddf24a68864f","properties":{"control_id":"SC-12","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-12-afabf2ca.json","targetId":"ctrl:nist-800-53:SC-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9410dcb93a1382eb7e0305ce79840b35ad2b921ea2a9c612e48a2c9c861db977","properties":{"rationale":"Issues certificates only from approved CAs, inventories/monitors them, and revokes promptly on compromise, the direct first-order defense against compromised/counterfeit certificates.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/risk-crypto-counterfeit-certificates-d9dcc5c5.json","targetId":"risk:crypto-counterfeit-certificates","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a96eab50d01760e6480aff0be977377cb9e8b4cff482f78d1f4ae4b1ad6e7220","properties":{"rationale":"Protecting private keys in HSMs and revoking compromised certs denies attackers the stolen-key/impersonation path used for eavesdropping and man-in-the-middle.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aef05ff264d1c00746124128b03a9dbc953f055f07cb074fb999c0823b83c8a1","properties":{"rationale":"Governs key generation, HSM storage, rotation, and destruction under dual control, directly remediating the poor-key-management facet that weakens encryption.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ed322e411e241abba50f4810b12a82d486be0fa3e964e7ea474959747aa90805","properties":{},"sourceDetailPath":"/data/v1/records/wf-c18-ca9e8eba.json","sourceId":"wf:C18","targetDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","targetId":"uc:UC-CRYPTO-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fcea20f9ffd805a6a2990a9bb69dbd963e4609bfa735af8c4578351236b0278b","properties":{"control_id":"SC-17","coverage":"partial","delta":"restricting managed trust stores to organization-approved trust anchors only","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-17-b6802187.json","targetId":"ctrl:nist-800-53:SC-17","type":"maps_to"}],"schemaVersion":1}
