id: "SC-12(03)" title: "Asymmetric Keys" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-12.03" priority: "P1" implementation_level: "system" parent: "SC-12" enhancement: True
Statement
Produce, control, and distribute asymmetric cryptographic keys using {{ insert: param, sc-12.03_odp }}.
Guidance
SP 800-56A, SP 800-56B , and SP 800-56C provide guidance on cryptographic key establishment schemes and key derivation methods. SP 800-57-1, SP 800-57-2 , and SP 800-57-3 provide guidance on cryptographic key management.
Assessment Objective: asymmetric cryptographic keys are produced using {{ insert: param, sc-12.03_odp }};
Assessment Objective: asymmetric cryptographic keys are controlled using {{ insert: param, sc-12.03_odp }};
Assessment Objective: asymmetric cryptographic keys are distributed using {{ insert: param, sc-12.03_odp }}.
System and communications protection policy
procedures addressing cryptographic key establishment and management
system design documentation
system configuration settings and associated documentation
system audit records
list of NSA-approved cryptographic products
list of approved PKI Class 3 and Class 4 certificates
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developer
organizational personnel with responsibilities for cryptographic key establishment or management
organizational personnel with responsibilities for PKI certificates
Mechanisms supporting and/or implementing asymmetric cryptographic key establishment and management