{"data":{"id":"SC-12","name":"Cryptographic Key Establishment and Management","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].","supplemental_guidance":"Cryptographic key management and establishment can be performed using manual procedures or automated mechanisms with supporting manual procedures. Organizations define key management requirements in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and specify appropriate options, parameters, and levels. Organizations manage trust stores to ensure that only approved trust anchors are part of such trust stores. This includes certificates with visibility external to organizational systems and certificates related to the internal operations of systems. [NIST CMVP] and [NIST CAVP] provide additional information on validated cryptographic modules and algorithms that can be used in cryptographic key management and establishment.","enhancements":[{"id":"SC-12(01)","name":"Availability","statement":"Maintain availability of information in the event of the loss of cryptographic keys by users.","baselines":["high"]},{"id":"SC-12(02)","name":"Symmetric Keys","statement":"Produce, control, and distribute symmetric cryptographic keys using [Selection (one): NIST FIPS-validated; NSA-approved] key management technology and processes.","baselines":[]},{"id":"SC-12(03)","name":"Asymmetric Keys","statement":"Produce, control, and distribute asymmetric cryptographic keys using [Selection (one): NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user’s private key; certificates issued in accordance with organization-defined requirements].","baselines":[]},{"id":"SC-12(04)","name":"PKI Certificates","withdrawn":true,"incorporated_into":["SC-12(03)"]},{"id":"SC-12(05)","name":"PKI Certificates / Hardware Tokens","withdrawn":true,"incorporated_into":["SC-12(03)"]},{"id":"SC-12(06)","name":"Physical Control of Keys","statement":"Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-12","name":"Cryptographic Key Establishment and Management","description":"Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].","discussion":"Cryptographic key management and establishment can be performed using manual procedures or automated mechanisms with supporting manual procedures. Organizations define key management requirements in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and specify appropriate options, parameters, and levels. Organizations manage trust stores to ensure that only approved trust anchors are part of such trust stores. This includes certificates with visibility external to organizational systems and certificates related to the internal operations of systems. [NIST CMVP] and [NIST CAVP] provide additional information on validated cryptographic modules and algorithms that can be used in cryptographic key management and establishment.","related_controls":["AC-17","AU-09","AU-10","CM-03","IA-03","IA-07","IA-13","SA-04","SA-08","SA-09","SC-08","SC-11","SC-13","SC-17","SC-20","SC-37","SC-40","SI-03","SI-07"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.14","A.8.24"],"iso_27002_2022":["5.14","8.24"],"cobit_2019":[],"pci_dss_v4":["3.5","3.6","3.7"],"nist_csf_2":["PR.DS-01","PR.DS-02"],"cis_controls_v8":[],"soc2_tsc":["CC6.1"],"finos_ccc":["CCC-C02"],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(h)"],"apra_cps_234":["Para 22-23"],"mas_trm":["10"],"pra_op_resilience":[],"bsi_grundschutz":["CON.1"],"anssi":["Hygiene.12","RGS.2.3","SecNumCloud.11.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.C(63)","IV.C(64)"],"gdpr":["Art.32(1)(a)","Rec.83"],"dora":["Art.9(3)"],"bio2":["5.14","8.24"],"rbi_csf":["ITGRCA.16"],"fisc":["FISC.T4","FISC.T11","FISC.T12"],"lgpd_bcb":["BCB.Art.3","BCB.PIX","LGPD.Art.46"],"hkma_tme1":["TME1.8.5","TME1.9.1","TME1.9.2","TME1.10.3","TME1.11.2"],"mlps_2":["8.1.2.2","8.1.10.7"],"dnb_good_practice":["DNB.18.3","DNB.18.5"],"cra":["CRA.I.2e"],"swift_cscf":["SWIFT.2.1","SWIFT.2.5A"],"cbb_tm":["TM-9"],"cbuae":["CR-8"],"nca_ecc":["2-8"],"qatar_nia":["CS"],"sama_csf":["3.4","4.3"],"uae_ia":["T8"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.4"],"cbe_csf":["CTO-3"],"cbn_csf":["Part3.3"],"popia":["s19"],"sa_js2":["JS2-8.3"],"bot_cyber":["Ch2.3","Ch2.7"],"cpmi_pfmi":["CG.PR"],"eba_ict":["3.8(b)"],"ecb_croe":["CROE.2.3.3"],"ffiec_is":["II.C.13(b)","II.C.15(c)","II.C.16","II.C.19"],"hipaa_sr":["§164.312(a)(2)(iv)","§164.312(e)(1)","§164.312(e)(2)(ii)"],"iosco_cyber":["PROT-3"],"nydfs_500":["500.15"],"sebi_cscrf":["DATALOC","PR.DS"],"cmmc_2":["SC"],"nerc_cip":["CIP-012-1"],"nrc_73_54":["RG5.71-A-SC"],"tsa_psd":[],"ieee_1686":["5.5"],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 8"],"awia":[],"iaea_nss":["Sec 5.6"],"pci_pts":["D","E"],"fips_140":["FIPS 140-3 §7.9"],"cbest":["CBEST.9"],"tiber_eu":[],"pci_hsm":["3","4","5","6","9"],"common_criteria":["CC Part 2 — FCS"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.30"],"fda_cyber":["SA-2"],"hitrust_csf":["10.c"],"iso_27799":["10.1","10.2","13.2","H.2"],"lloyds_ms":["BP2.1"],"naic_ds":["4-encryption","4B"],"nhs_dspt":["NDG-9.6"],"pra_ss1_23":[],"solvency_ii":["DR.266-DataSec","EIOPA-ICT-4.7"],"owasp_masvs_v2":["MASVS-CRYPTO-2","MASVS-STORAGE-1"],"csa_ccm_v4":["CEK-01","CEK-02","CEK-08","CEK-09","CEK-10","CEK-11","CEK-12","CEK-13","CEK-14","CEK-15","CEK-16","CEK-17","CEK-18","CEK-19","CEK-20","CEK-21"],"csa_aicm":["CEK-01","CEK-02","CEK-08","CEK-09","CEK-10","CEK-11","CEK-12","CEK-13","CEK-14","CEK-15","CEK-16","CEK-17","CEK-18","CEK-19","CEK-20","CEK-21"],"ccss_v9":["1.01.1","1.01.2","1.01.4","1.01.5","1.01.6","1.01.7","1.02.1","1.02.2","1.02.3","1.02.4","1.02.5","1.02.6","1.03.1","1.03.2","1.03.6","1.05.5","1.06.1"],"mica":["Art.40(1)","Art.55(1)","Art.63(1)","Art.67(1)","Art.76(1)","Art.97(1)"],"basel_sco60":["SCO60.11","SCO60.21","SCO60.23","SCO60.41","SCO60.51","SCO60.61","SCO60.63","SCO60.64","SCO60.65","SCO60.66"],"bssc":["GSP-13","KMS-01","KMS-02","KMS-03","KMS-04","KMS-05","KMS-07","KMS-08","KMS-09","KMS-10","NOS-08","TIS-07"],"sec_custody_digital":["SEC-CD-02","SEC-CD-03","SEC-CD-06","SEC-CD-07","SEC-CD-08","SEC-CD-12","SEC-CD-13","SEC-CD-16"],"dpdpa":["Act.8(5)","Rules.6(1)(a)","Rules.Sch1.B.2","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Proper cryptographic key management ensures that software deployment tools authenticate using well-managed keys, preventing adversaries from leveraging weak or stolen deployment credentials to distribute malicious payloads."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic key management directly addresses unsecured credentials by establishing secure key-storage practices, rotation policies, and access controls that prevent exposure of cryptographic secrets in plaintext."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Proper key management enables detection of unauthorized encrypted C2 channels by maintaining an inventory of legitimate cryptographic keys and certificates, identifying anomalous encryption that uses unmanaged or unauthorized keys."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic key management controls SSH authorized key deployment through centralized key lifecycle management, preventing adversaries from planting unauthorized public keys by enforcing key registration and approval processes."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Key management practices prevent credentials in files by establishing secure key-storage mechanisms (HSMs, vaults, secure enclaves) that eliminate the need to store cryptographic material in plaintext configuration files."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper key management prevents credential storage in the Windows registry by providing secure alternatives for key storage that do not rely on registry-based credential persistence."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic key management directly protects private keys through secure generation, storage in HSMs or key vaults, and access controls that prevent unauthorized extraction of TLS, SSH, and code-signing keys."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Key management controls SSH session security by enforcing key rotation, revoking compromised keys, and maintaining authorized-key inventories that prevent SSH hijacking through stolen or planted key material."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Proper management of symmetric cryptographic keys enables identification of unauthorized encryption by maintaining inventories of legitimate symmetric keys, detecting C2 channels using unrecognized key material."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic key management controls asymmetric key pairs and certificates, enabling detection of adversary C2 channels that use self-signed or unauthorized certificates for encrypted command-and-control communications."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-01 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-011","SP-015","SP-022","SP-026","SP-027","SP-028","SP-032","SP-033","SP-034","SP-037","SP-039","SP-040","SP-041","SP-050","SP-051","SP-052","SP-053","SP-054"]}}