# SC-17 Public Key Infrastructure Certificates

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Issue public key certificates under an [Assignment: organization-defined certificate policy] or obtain public key certificates from an approved service provider; and b. Include only approved trust anchors in trust stores or certificate stores managed by the organization.
Guidance: Public key infrastructure (PKI) certificates are certificates with visibility external to organizational systems and certificates related to the internal operations of systems, such as application-specific time services. In cryptographic systems with a hierarchical structure, a trust anchor is an authoritative source (i.e., a certificate authority) for which trust is assumed and not derived. A root certificate for a PKI system is an example of a trust anchor. A trust store or certificate store maintains a list of trusted root certificates.

## Patterns that use it (7)
- Critical (2): SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (3): SP-033 Passkey Authentication; SP-050 Mobile Security Architecture (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft)
- Standard (2): SP-022 Board of Directors Room; SP-039 Client-Side Encryption and Data Privacy

## Clauses by framework (41 frameworks)
- iso_27001_2022: A.8.24
- soc2_tsc: CC6.1
- anssi: Hygiene.12, RGS.2.3, SecNumCloud.11.1
- osfi_b13: B-13.3.2
- finma_circular: IV.C(63), IV.C(64)
- gdpr: Art.32(1)(a), Rec.83
- dora: Art.9(3)
- rbi_csf: ITGRCA.16
- fisc: FISC.T4
- hkma_tme1: TME1.9.1, TME1.9.2, TME1.9.3
- dnb_good_practice: DNB.18.3
- cbuae: CR-8
- nca_ecc: 2-8
- qatar_nia: CS
- sama_csf: 3.4
- bog_cisd: CISD-VI
- bom_ctrm: 3.4
- cbe_csf: CTO-3
- sa_js2: JS2-8.3
- bot_cyber: Ch2.7
- ffiec_is: II.C.19
- hipaa_sr: §164.312(e)(2)(ii)
- cmmc_2: SC
- pci_pts: D
- fips_140: FIPS 140-3 §7.9
- pci_hsm: 9
- common_criteria: CC Part 2 — FCS
- fda_21_cfr_11: §11.30
- fda_cyber: SA-2
- hitrust_csf: 10.c
- iso_27799: 10.2
- nhs_dspt: NDG-9.6
- solvency_ii: EIOPA-ICT-4.7
- owasp_masvs_v2: MASVS-CRYPTO-2, MASVS-NETWORK-2
- csa_ccm_v4: CEK-13
- csa_aicm: CEK-13
- ccss_v9: 1.02.4
- mica: Art.63(1), Art.67(1)
- basel_sco60: SCO60.11, SCO60.61
- bssc: KMS-01
- sec_custody_digital: SEC-CD-02, SEC-CD-06
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-17
- Clauses only: /api/v1/controls/SC-17?fields=mappings
- Page for people: /controls/sc-17/
