Skip to main content

💼 SC-12 CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT

  • ID: /frameworks/nist-sp-800-53-r4/sc/12

Description

The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].

Similar

  • Internal
    • ID: dec-c-2411c0ba

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 PR.DS-1: Data-at-rest is protected1530no data
💼 NIST CSF v1.1 → 💼 PR.DS-2: Data-in-transit is protected1653no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 SC-12 (1) AVAILABILITYno data
💼 SC-12 (2) SYMMETRIC KEYS11no data
💼 SC-12 (3) ASYMMETRIC KEYS11no data
💼 SC-12 (4) PKI CERTIFICATESno data
💼 SC-12 (5) PKI CERTIFICATES _ HARDWARE TOKENSno data

Policies (5)

PolicyLogic CountFlagsCompliance
🛡️ AWS Account Root User has active access keys🟢1🟢 x6no data
🛡️ AWS IAM User Access Keys are not rotated every 90 days or less🟢1🟢 x6no data
🛡️ AWS IAM User has more than one active access key🟢1🟢 x6no data
🛡️ AWS IAM User with console and programmatic access set during the initial creation🟢⚪🟢 x2, ⚪ x1no data
🛡️ Google Project with KMS keys has a principal with Owner role🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-0a7801fb1
✉️ dec-x-307950161
✉️ dec-x-b10e98af1
✉️ dec-x-bcb0c78f1