id: "IA-13(01)" title: "Protection of Cryptographic Keys" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-13.01" priority: "P1" implementation_level: "system" parent: "IA-13" enhancement: True


Statement

Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.

Guidance

Identity assertions and access tokens are typically digitally signed. The private keys used to sign these assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.

Assessment Objective: cryptographic keys that protect access tokens are generated;

Assessment Objective: cryptographic keys that protect access tokens are managed;

Assessment Objective: cryptographic keys that protect access tokens are protected from disclosure; and

Assessment Objective: cryptographic keys that protect access tokens are protected from disclosure and misuse

Identification and authentication policy;

procedures addressing cryptographic key establishment and management;

system design documentation;

cryptographic mechanisms;

system configuration settings and associated documentation;

system security plan;

other relevant documents or records

System/network administrators;

organizational personnel with information security responsibilities;

organizational personnel with responsibilities for cryptographic key establishment and/or management

Organizational processes for cryptographic key management;

cryptographic modules generating, storing, and using cryptographic keys