Skip to main content

πŸ’Ό SC-12 CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT

Description​

The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].

Similar​

  • Internal
    • ID: dec-c-2411c0ba

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.DS-1: Data-at-rest is protected1519
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.DS-2: Data-in-transit is protected1421

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SC-12 (1) AVAILABILITY
πŸ’Ό SC-12 (2) SYMMETRIC KEYS11
πŸ’Ό SC-12 (3) ASYMMETRIC KEYS11
πŸ’Ό SC-12 (4) PKI CERTIFICATES
πŸ’Ό SC-12 (5) PKI CERTIFICATES _ HARDWARE TOKENS

Policies (4)​

PolicyLogic CountFlags
πŸ“ AWS Account Root User has active access keys 🟒1🟒 x6
πŸ“ AWS IAM User Access Keys are not rotated every 90 days or less 🟒1🟒 x6
πŸ“ AWS IAM User has more than one active access key 🟒1🟒 x6
πŸ“ AWS IAM User with console and programmatic access set during the initial creation 🟒🟒 x3

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-0a7801fb1
βœ‰οΈ dec-x-307950161
βœ‰οΈ dec-x-b10e98af1
βœ‰οΈ dec-x-bcb0c78f1