id: "SC-12(06)" title: "Physical Control of Keys" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-12.06" priority: "P1" implementation_level: "system" parent: "SC-12" enhancement: True
Statement
Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.
Guidance
For organizations that use external service providers (e.g., cloud service or data center providers), physical control of cryptographic keys provides additional assurance that information stored by such external providers is not subject to unauthorized disclosure or modification.
Assessment Objective
physical control of cryptographic keys is maintained when stored information is encrypted by external service providers.
System and communications protection policy
procedures addressing cryptographic key establishment, management, and recovery
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel with responsibilities for cryptographic key establishment or management
Mechanisms supporting and/or implementing cryptographic key establishment and management