Control statement
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Organization-defined: requirements].
Discussion
Cryptographic key management and establishment can be performed using manual procedures or automated mechanisms with supporting manual procedures. Organizations define key management requirements in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and specify appropriate options, parameters, and levels. Organizations manage trust stores to ensure that only approved trust anchors are part of such trust stores. This includes certificates with visibility external to organizational systems and certificates related to the internal operations of systems. [NIST CMVP](#1acdc775-aafb-4d11-9341-dc6a822e9d38) and [NIST CAVP](#84dc1b0c-acb7-4269-84c4-00dbabacd78c) provide additional information on validated cryptographic modules and algorithms that can be used in cryptographic key management and establishment.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Cryptographic Key Establishment and Management as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- network and trust-boundary diagrams
- firewall and gateway configurations
- cryptographic configuration and key records
- segmentation and isolation test results
Common failure patterns
- diagrams omit cloud and third-party paths
- encryption enabled without key governance
- flat trust zones allow unnecessary lateral movement
- boundary rules accumulate without owner review
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SC-12[01]cryptographic keys are established when cryptography is employed within the system in accordance with [Organization-defined: requirements];
- SC-12[02]cryptographic keys are managed when cryptography is employed within the system in accordance with [Organization-defined: requirements].
Examine
- System and communications protection policy
- procedures addressing cryptographic key establishment and management
- system design documentation
- cryptographic mechanisms
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with responsibilities for cryptographic key establishment and/or management
Test
- Mechanisms supporting and/or implementing cryptographic key establishment and management
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-171 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SC-12(1) — Availability
Maintain availability of information in the event of the loss of cryptographic keys by users.
Official discussion
Escrowing of encryption keys is a common practice for ensuring availability in the event of key loss. A forgotten passphrase is an example of losing a cryptographic key.
Assessment objectives and methods
information availability is maintained in the event of the loss of cryptographic keys by users.
Examine
- System and communications protection policy
- procedures addressing cryptographic key establishment, management, and recovery
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with responsibilities for cryptographic key establishment or management
Test
- Mechanisms supporting and/or implementing cryptographic key establishment and management
SC-12(2) — Symmetric Keys
Produce, control, and distribute symmetric cryptographic keys using [Organization-defined: sc-12.02_odp] key management technology and processes.
Official discussion
[SP 800-56A](#20957dbb-6a1e-40a2-b38a-66f67d33ac2e), [SP 800-56B](#0d083d8a-5cc6-46f1-8d79-3081d42bcb75) , and [SP 800-56C](#eef62b16-c796-4554-955c-505824135b8a) provide guidance on cryptographic key establishment schemes and key derivation methods. [SP 800-57-1](#110e26af-4765-49e1-8740-6750f83fcda1), [SP 800-57-2](#e7942589-e267-4a5a-a3d9-f39a7aae81f0) , and [SP 800-57-3](#8306620b-1920-4d73-8b21-12008528595f) provide guidance on cryptographic key management.
Organization-defined parameters (1)
Assessment objectives and methods
- SC-12(02)[01]symmetric cryptographic keys are produced using [Organization-defined: sc-12.02_odp] key management technology and processes;
- SC-12(02)[02]symmetric cryptographic keys are controlled using [Organization-defined: sc-12.02_odp] key management technology and processes;
- SC-12(02)[03]symmetric cryptographic keys are distributed using [Organization-defined: sc-12.02_odp] key management technology and processes.
Examine
- System and communications protection policy
- procedures addressing cryptographic key establishment and management
- system design documentation
- system configuration settings and associated documentation
- system audit records
- list of FIPS-validated cryptographic products
- list of NSA-approved cryptographic products
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with responsibilities for cryptographic key establishment or management
Test
- Mechanisms supporting and/or implementing symmetric cryptographic key establishment and management
SC-12(3) — Asymmetric Keys
Produce, control, and distribute asymmetric cryptographic keys using [Organization-defined: sc-12.03_odp].
Official discussion
[SP 800-56A](#20957dbb-6a1e-40a2-b38a-66f67d33ac2e), [SP 800-56B](#0d083d8a-5cc6-46f1-8d79-3081d42bcb75) , and [SP 800-56C](#eef62b16-c796-4554-955c-505824135b8a) provide guidance on cryptographic key establishment schemes and key derivation methods. [SP 800-57-1](#110e26af-4765-49e1-8740-6750f83fcda1), [SP 800-57-2](#e7942589-e267-4a5a-a3d9-f39a7aae81f0) , and [SP 800-57-3](#8306620b-1920-4d73-8b21-12008528595f) provide guidance on cryptographic key management.
Organization-defined parameters (1)
Assessment objectives and methods
- SC-12(03)[01]asymmetric cryptographic keys are produced using [Organization-defined: sc-12.03_odp];
- SC-12(03)[02]asymmetric cryptographic keys are controlled using [Organization-defined: sc-12.03_odp];
- SC-12(03)[03]asymmetric cryptographic keys are distributed using [Organization-defined: sc-12.03_odp].
Examine
- System and communications protection policy
- procedures addressing cryptographic key establishment and management
- system design documentation
- system configuration settings and associated documentation
- system audit records
- list of NSA-approved cryptographic products
- list of approved PKI Class 3 and Class 4 certificates
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with responsibilities for cryptographic key establishment or management
- organizational personnel with responsibilities for PKI certificates
Test
- Mechanisms supporting and/or implementing asymmetric cryptographic key establishment and management
SC-12(4) — PKI Certificates
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SC-12(5) — PKI Certificates / Hardware Tokens
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SC-12(6) — Physical Control of Keys
Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.
Official discussion
For organizations that use external service providers (e.g., cloud service or data center providers), physical control of cryptographic keys provides additional assurance that information stored by such external providers is not subject to unauthorized disclosure or modification.
Assessment objectives and methods
physical control of cryptographic keys is maintained when stored information is encrypted by external service providers.
Examine
- System and communications protection policy
- procedures addressing cryptographic key establishment, management, and recovery
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with responsibilities for cryptographic key establishment or management
Test
- Mechanisms supporting and/or implementing cryptographic key establishment and management
Authoritative sources
- FIPS 140-3 ↗
- SP 800-56A ↗
- SP 800-56B ↗
- SP 800-56C ↗
- SP 800-57-1 ↗
- SP 800-57-2 ↗
- SP 800-57-3 ↗
- SP 800-63-3 ↗
- IR 7956 ↗
- IR 7966 ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.