Skip to main content

SC-12 Cryptographic Key Establishment and Management

Description

When encryption is used, appropriate key management procedures are crucial. The university is responsible to manage cryptographic keys for required cryptography employed within the university using automated mechanisms with supported procedures.

Applicability

  • The owner of an information resource, or designee, is responsible for implementing this control.

Implementation

  • An information resource owner, or designee, is responsible to:

  • 1Manage cryptographic keys using automated mechanisms with supporting procedures where feasible.

    • 1.1When automated mechanisms are not feasible, manual key management may be used along with sufficient supporting procedures and documentation.
  • 2Appropriately secure public and private keys.

  • 3Maintain availability of information in the event of the loss of cryptographic keys by users.

    • 3.1Recovery of encryption keys should be part of business continuity planning with the exception of data used by a single individual (e.g., an individual faculty member’s grade book working copy).