Skip to main content

💼 SC-12 CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT

Description

The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].

Similar

  • Internal
    • ID: dec-c-2411c0ba

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST CSF v1.1 → 💼 PR.DS-1: Data-at-rest is protected1528
💼 NIST CSF v1.1 → 💼 PR.DS-2: Data-in-transit is protected1631

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags
💼 SC-12 (1) AVAILABILITY
💼 SC-12 (2) SYMMETRIC KEYS11
💼 SC-12 (3) ASYMMETRIC KEYS11
💼 SC-12 (4) PKI CERTIFICATES
💼 SC-12 (5) PKI CERTIFICATES _ HARDWARE TOKENS

Policies (4)

PolicyLogic CountFlags
📝 AWS Account Root User has active access keys 🟢1🟢 x6
📝 AWS IAM User Access Keys are not rotated every 90 days or less 🟢1🟢 x6
📝 AWS IAM User has more than one active access key 🟢1🟢 x6
📝 AWS IAM User with console and programmatic access set during the initial creation 🟢🟢 x3

Internal Rules

RulePoliciesFlags
✉️ dec-x-0a7801fb1
✉️ dec-x-307950161
✉️ dec-x-b10e98af1
✉️ dec-x-bcb0c78f1