id: "SC-12(03)" title: "Asymmetric Keys" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-12.03" priority: "P1" implementation_level: "system" parent: "SC-12" enhancement: True


Statement

Produce, control, and distribute asymmetric cryptographic keys using {{ insert: param, sc-12.03_odp }}.

Guidance

SP 800-56A, SP 800-56B , and SP 800-56C provide guidance on cryptographic key establishment schemes and key derivation methods. SP 800-57-1, SP 800-57-2 , and SP 800-57-3 provide guidance on cryptographic key management.

Assessment Objective: asymmetric cryptographic keys are produced using {{ insert: param, sc-12.03_odp }};

Assessment Objective: asymmetric cryptographic keys are controlled using {{ insert: param, sc-12.03_odp }};

Assessment Objective: asymmetric cryptographic keys are distributed using {{ insert: param, sc-12.03_odp }}.

System and communications protection policy

procedures addressing cryptographic key establishment and management

system design documentation

system configuration settings and associated documentation

system audit records

list of NSA-approved cryptographic products

list of approved PKI Class 3 and Class 4 certificates

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel with responsibilities for cryptographic key establishment or management

organizational personnel with responsibilities for PKI certificates

Mechanisms supporting and/or implementing asymmetric cryptographic key establishment and management