id: "SC-12(06)" title: "Physical Control of Keys" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-12.06" priority: "P1" implementation_level: "system" parent: "SC-12" enhancement: True


Statement

Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.

Guidance

For organizations that use external service providers (e.g., cloud service or data center providers), physical control of cryptographic keys provides additional assurance that information stored by such external providers is not subject to unauthorized disclosure or modification.

Assessment Objective

physical control of cryptographic keys is maintained when stored information is encrypted by external service providers.

System and communications protection policy

procedures addressing cryptographic key establishment, management, and recovery

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with responsibilities for cryptographic key establishment or management

Mechanisms supporting and/or implementing cryptographic key establishment and management