# SC-12 Cryptographic Key Establishment and Management

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].
Guidance: Cryptographic key management and establishment can be performed using manual procedures or automated mechanisms with supporting manual procedures. Organizations define key management requirements in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and specify appropriate options, parameters, and levels. Organizations manage trust stores to ensure that only approved trust anchors are part of such trust stores. This includes certificates with visibility external to organizational systems and certificates related to the internal operations of systems. [NIST CMVP] and [NIST CAVP] provide additional information on validated cryptographic modules and algorithms that can be used in cryptographic key management and establishment.

## Enhancements (4)
- SC-12(01) Availability. Baselines: high
- SC-12(02) Symmetric Keys
- SC-12(03) Asymmetric Keys
- SC-12(06) Physical Control of Keys
Withdrawn by NIST: SC-12(04) (now in SC-12(03)); SC-12(05) (now in SC-12(03)).
Each enhancement's statement: /api/v1/controls/SC-12?fields=enhancements

## Patterns that use it (19)
- Critical (10): SP-026 PCI Full Environment; SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-039 Client-Side Encryption and Data Privacy; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-050 Mobile Security Architecture (draft); SP-051 Tokenised Asset Security Architecture (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft); SP-053 Zero-Knowledge Proof Architecture (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (9): SP-001 Client Module; SP-002 Server Module; SP-011 Cloud Computing Pattern; SP-015 Secure Remote Working; SP-022 Board of Directors Room; SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline Pattern; SP-034 Cyber Resilience; SP-037 Privileged User Management

## Clauses by framework (75 frameworks)
- iso_27001_2022: A.5.14, A.8.24. OSA's own, not in NIST's crosswalk: A.5.14
- iso_27002_2022: 5.14, 8.24
- pci_dss_v4: 3.5, 3.6, 3.7
- nist_csf_2: PR.DS-01, PR.DS-02
- soc2_tsc: CC6.1
- finos_ccc: CCC-C02
- nis2: Art. 21(2)(h)
- apra_cps_234: Para 22-23
- mas_trm: 10
- bsi_grundschutz: CON.1
- anssi: Hygiene.12, RGS.2.3, SecNumCloud.11.1
- osfi_b13: B-13.3.2
- finma_circular: IV.C(63), IV.C(64)
- gdpr: Art.32(1)(a), Rec.83
- dora: Art.9(3)
- bio2: 5.14, 8.24
- rbi_csf: ITGRCA.16
- fisc: FISC.T4, FISC.T11, FISC.T12
- lgpd_bcb: BCB.Art.3, BCB.PIX, LGPD.Art.46
- hkma_tme1: TME1.8.5, TME1.9.1, TME1.9.2, TME1.10.3, TME1.11.2
- mlps_2: 8.1.2.2, 8.1.10.7
- dnb_good_practice: DNB.18.3, DNB.18.5
- cra: CRA.I.2e
- swift_cscf: SWIFT.2.1, SWIFT.2.5A
- cbb_tm: TM-9
- cbuae: CR-8
- nca_ecc: 2-8
- qatar_nia: CS
- sama_csf: 3.4, 4.3
- uae_ia: T8
- bog_cisd: CISD-VI
- bom_ctrm: 3.4
- cbe_csf: CTO-3
- cbn_csf: Part3.3
- popia: s19
- sa_js2: JS2-8.3
- bot_cyber: Ch2.3, Ch2.7
- cpmi_pfmi: CG.PR
- eba_ict: 3.8(b)
- ecb_croe: CROE.2.3.3
- ffiec_is: II.C.13(b), II.C.15(c), II.C.16, II.C.19
- hipaa_sr: §164.312(a)(2)(iv), §164.312(e)(1), §164.312(e)(2)(ii)
- iosco_cyber: PROT-3
- nydfs_500: 500.15
- sebi_cscrf: DATALOC, PR.DS
- cmmc_2: SC
- nerc_cip: CIP-012-1
- nrc_73_54: RG5.71-A-SC
- ieee_1686: 5.5
- api_1164: Sec 8
- iaea_nss: Sec 5.6
- pci_pts: D, E
- fips_140: FIPS 140-3 §7.9
- cbest: CBEST.9
- pci_hsm: 3, 4, 5, 6, 9
- common_criteria: CC Part 2 — FCS
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.30
- fda_cyber: SA-2
- hitrust_csf: 10.c
- iso_27799: 10.1, 10.2, 13.2, H.2
- lloyds_ms: BP2.1
- naic_ds: 4-encryption, 4B
- nhs_dspt: NDG-9.6
- solvency_ii: DR.266-DataSec, EIOPA-ICT-4.7
- owasp_masvs_v2: MASVS-CRYPTO-2, MASVS-STORAGE-1
- csa_ccm_v4: CEK-01, CEK-02, CEK-08, CEK-09, CEK-10, CEK-11, CEK-12, CEK-13, CEK-14, CEK-15, CEK-16, CEK-17, CEK-18, CEK-19, CEK-20, CEK-21
- csa_aicm: CEK-01, CEK-02, CEK-08, CEK-09, CEK-10, CEK-11, CEK-12, CEK-13, CEK-14, CEK-15, CEK-16, CEK-17, CEK-18, CEK-19, CEK-20, CEK-21
- ccss_v9: 1.01.1, 1.01.2, 1.01.4, 1.01.5, 1.01.6, 1.01.7, 1.02.1, 1.02.2, 1.02.3, 1.02.4, 1.02.5, 1.02.6, 1.03.1, 1.03.2, 1.03.6, 1.05.5, 1.06.1
- mica: Art.40(1), Art.55(1), Art.63(1), Art.67(1), Art.76(1), Art.97(1)
- basel_sco60: SCO60.11, SCO60.21, SCO60.23, SCO60.41, SCO60.51, SCO60.61, SCO60.63, SCO60.64, SCO60.65, SCO60.66
- bssc: GSP-13, KMS-01, KMS-02, KMS-03, KMS-04, KMS-05, KMS-07, KMS-08, KMS-09, KMS-10, NOS-08, TIS-07
- sec_custody_digital: SEC-CD-02, SEC-CD-03, SEC-CD-06, SEC-CD-07, SEC-CD-08, SEC-CD-12, SEC-CD-13, SEC-CD-16
- dpdpa: Act.8(5), Rules.6(1)(a), Rules.Sch1.B.2, Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-12
- Clauses only: /api/v1/controls/SC-12?fields=mappings
- Page for people: /controls/sc-12/
