id: "SC-28(03)" title: "Cryptographic Keys" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-28.03" priority: "P1" implementation_level: "system" parent: "SC-28" enhancement: True
Statement
Provide protected storage for cryptographic keys {{ insert: param, sc-28.03_odp.01 }}.
Guidance
A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.
Assessment Objective
protected storage for cryptographic keys is provided using {{ insert: param, sc-28.03_odp.01 }}.
System and communications protection policy
procedures addressing the protection of information at rest
system design documentation
system configuration settings and associated documentation
cryptographic mechanisms and associated configuration documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
Mechanisms supporting and/or implementing hardware-based key store protection