id: "SC-28(03)" title: "Cryptographic Keys" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-28.03" priority: "P1" implementation_level: "system" parent: "SC-28" enhancement: True


Statement

Provide protected storage for cryptographic keys {{ insert: param, sc-28.03_odp.01 }}.

Guidance

A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.

Assessment Objective

protected storage for cryptographic keys is provided using {{ insert: param, sc-28.03_odp.01 }}.

System and communications protection policy

procedures addressing the protection of information at rest

system design documentation

system configuration settings and associated documentation

cryptographic mechanisms and associated configuration documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

Mechanisms supporting and/or implementing hardware-based key store protection