{"data":{"id":"SC-17","name":"Public Key Infrastructure Certificates","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. Issue public key certificates under an [Assignment: organization-defined certificate policy] or obtain public key certificates from an approved service provider; and\nb. Include only approved trust anchors in trust stores or certificate stores managed by the organization.","supplemental_guidance":"Public key infrastructure (PKI) certificates are certificates with visibility external to organizational systems and certificates related to the internal operations of systems, such as application-specific time services. In cryptographic systems with a hierarchical structure, a trust anchor is an authoritative source (i.e., a certificate authority) for which trust is assumed and not derived. A root certificate for a PKI system is an example of a trust anchor. A trust store or certificate store maintains a list of trusted root certificates.","enhancements":[],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-17","name":"Public Key Infrastructure Certificates","description":"a. Issue public key certificates under an [Assignment: organization-defined certificate policy] or obtain public key certificates from an approved service provider; and\nb. Include only approved trust anchors in trust stores or certificate stores managed by the organization.","discussion":"Public key infrastructure (PKI) certificates are certificates with visibility external to organizational systems and certificates related to the internal operations of systems, such as application-specific time services. In cryptographic systems with a hierarchical structure, a trust anchor is an authoritative source (i.e., a certificate authority) for which trust is assumed and not derived. A root certificate for a PKI system is an example of a trust anchor. A trust store or certificate store maintains a list of trusted root certificates.","related_controls":["AU-10","IA-05","SC-12"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds text to include only approved trust anchors in trust stores or certificate stores managed by the organization  Discussion expanded to address trust anchors"}},"compliance_mappings":{"iso_27001_2022":["A.8.24"],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":["CC6.1"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.12","RGS.2.3","SecNumCloud.11.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.C(63)","IV.C(64)"],"gdpr":["Art.32(1)(a)","Rec.83"],"dora":["Art.9(3)"],"bio2":[],"rbi_csf":["ITGRCA.16"],"fisc":["FISC.T4"],"lgpd_bcb":[],"hkma_tme1":["TME1.9.1","TME1.9.2","TME1.9.3"],"mlps_2":[],"dnb_good_practice":["DNB.18.3"],"cra":[],"swift_cscf":[],"cbuae":["CR-8"],"nca_ecc":["2-8"],"qatar_nia":["CS"],"sama_csf":["3.4"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.4"],"cbe_csf":["CTO-3"],"sa_js2":["JS2-8.3"],"bot_cyber":["Ch2.7"],"ffiec_is":["II.C.19"],"hipaa_sr":["§164.312(e)(2)(ii)"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["D"],"fips_140":["FIPS 140-3 §7.9"],"cbest":[],"tiber_eu":[],"pci_hsm":["9"],"common_criteria":["CC Part 2 — FCS"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.30"],"fda_cyber":["SA-2"],"hitrust_csf":["10.c"],"iso_27799":["10.2"],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":["NDG-9.6"],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.7"],"owasp_masvs_v2":["MASVS-CRYPTO-2","MASVS-NETWORK-2"],"csa_ccm_v4":["CEK-13"],"csa_aicm":["CEK-13"],"ccss_v9":["1.02.4"],"mica":["Art.63(1)","Art.67(1)"],"basel_sco60":["SCO60.11","SCO60.61"],"bssc":["KMS-01"],"sec_custody_digital":["SEC-CD-02","SEC-CD-06"],"dpdpa":[]},"attack_techniques":[{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"PKI certificate management ensures software deployment tools authenticate using validated certificates, preventing adversaries from injecting unauthorized packages through untrusted or forged deployment channels."},{"id":"T1606","name":"Forge Web Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"A well-managed PKI with controlled certificate issuance and key protection prevents adversaries from obtaining the signing keys necessary to forge SAML tokens, web cookies, and other authentication credentials."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-02: iso_27001_2022 clauses taken from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR, v1.0.0). OSA had none. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-022","SP-033","SP-039","SP-040","SP-050","SP-052","SP-054"]}}