Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

SC-12 — Cryptographic Key Establishment and Management

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

6Enhancements
1Parameters
3Baseline memberships
3Assessment methods

SC — System and Communications Protection · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Organization-defined: requirements].

Official NIST discussion

Discussion

Cryptographic key management and establishment can be performed using manual procedures or automated mechanisms with supporting manual procedures. Organizations define key management requirements in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and specify appropriate options, parameters, and levels. Organizations manage trust stores to ensure that only approved trust anchors are part of such trust stores. This includes certificates with visibility external to organizational systems and certificates related to the internal operations of systems. [NIST CMVP](#1acdc775-aafb-4d11-9341-dc6a822e9d38) and [NIST CAVP](#84dc1b0c-acb7-4269-84c4-00dbabacd78c) provide additional information on validated cryptographic modules and algorithms that can be used in cryptographic key management and establishment.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

requirementsrequirements for key generation, distribution, storage, access, and destruction are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Cryptographic Key Establishment and Management as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • network and trust-boundary diagrams
  • firewall and gateway configurations
  • cryptographic configuration and key records
  • segmentation and isolation test results

Common failure patterns

  • diagrams omit cloud and third-party paths
  • encryption enabled without key governance
  • flat trust zones allow unnecessary lateral movement
  • boundary rules accumulate without owner review

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SC-12[01]cryptographic keys are established when cryptography is employed within the system in accordance with [Organization-defined: requirements];
  2. SC-12[02]cryptographic keys are managed when cryptography is employed within the system in accordance with [Organization-defined: requirements].

Examine

  • System and communications protection policy
  • procedures addressing cryptographic key establishment and management
  • system design documentation
  • cryptographic mechanisms
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibilities for cryptographic key establishment and/or management

Test

  • Mechanisms supporting and/or implementing cryptographic key establishment and management
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-171 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SC-12(1) — Availability

High

Maintain availability of information in the event of the loss of cryptographic keys by users.

Official discussion

Escrowing of encryption keys is a common practice for ensuring availability in the event of key loss. A forgotten passphrase is an example of losing a cryptographic key.

Assessment objectives and methods

information availability is maintained in the event of the loss of cryptographic keys by users.

Examine

  • System and communications protection policy
  • procedures addressing cryptographic key establishment, management, and recovery
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibilities for cryptographic key establishment or management

Test

  • Mechanisms supporting and/or implementing cryptographic key establishment and management
Official NIST control enhancement

SC-12(2) — Symmetric Keys

Produce, control, and distribute symmetric cryptographic keys using [Organization-defined: sc-12.02_odp] key management technology and processes.

Official discussion

[SP 800-56A](#20957dbb-6a1e-40a2-b38a-66f67d33ac2e), [SP 800-56B](#0d083d8a-5cc6-46f1-8d79-3081d42bcb75) , and [SP 800-56C](#eef62b16-c796-4554-955c-505824135b8a) provide guidance on cryptographic key establishment schemes and key derivation methods. [SP 800-57-1](#110e26af-4765-49e1-8740-6750f83fcda1), [SP 800-57-2](#e7942589-e267-4a5a-a3d9-f39a7aae81f0) , and [SP 800-57-3](#8306620b-1920-4d73-8b21-12008528595f) provide guidance on cryptographic key management.

Organization-defined parameters (1)
sc-12.02_odp
Assessment objectives and methods
  1. SC-12(02)[01]symmetric cryptographic keys are produced using [Organization-defined: sc-12.02_odp] key management technology and processes;
  2. SC-12(02)[02]symmetric cryptographic keys are controlled using [Organization-defined: sc-12.02_odp] key management technology and processes;
  3. SC-12(02)[03]symmetric cryptographic keys are distributed using [Organization-defined: sc-12.02_odp] key management technology and processes.

Examine

  • System and communications protection policy
  • procedures addressing cryptographic key establishment and management
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • list of FIPS-validated cryptographic products
  • list of NSA-approved cryptographic products
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with responsibilities for cryptographic key establishment or management

Test

  • Mechanisms supporting and/or implementing symmetric cryptographic key establishment and management
Official NIST control enhancement

SC-12(3) — Asymmetric Keys

Produce, control, and distribute asymmetric cryptographic keys using [Organization-defined: sc-12.03_odp].

Official discussion

[SP 800-56A](#20957dbb-6a1e-40a2-b38a-66f67d33ac2e), [SP 800-56B](#0d083d8a-5cc6-46f1-8d79-3081d42bcb75) , and [SP 800-56C](#eef62b16-c796-4554-955c-505824135b8a) provide guidance on cryptographic key establishment schemes and key derivation methods. [SP 800-57-1](#110e26af-4765-49e1-8740-6750f83fcda1), [SP 800-57-2](#e7942589-e267-4a5a-a3d9-f39a7aae81f0) , and [SP 800-57-3](#8306620b-1920-4d73-8b21-12008528595f) provide guidance on cryptographic key management.

Organization-defined parameters (1)
sc-12.03_odp
Assessment objectives and methods
  1. SC-12(03)[01]asymmetric cryptographic keys are produced using [Organization-defined: sc-12.03_odp];
  2. SC-12(03)[02]asymmetric cryptographic keys are controlled using [Organization-defined: sc-12.03_odp];
  3. SC-12(03)[03]asymmetric cryptographic keys are distributed using [Organization-defined: sc-12.03_odp].

Examine

  • System and communications protection policy
  • procedures addressing cryptographic key establishment and management
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • list of NSA-approved cryptographic products
  • list of approved PKI Class 3 and Class 4 certificates
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with responsibilities for cryptographic key establishment or management
  • organizational personnel with responsibilities for PKI certificates

Test

  • Mechanisms supporting and/or implementing asymmetric cryptographic key establishment and management
Official NIST control enhancement

SC-12(4) — PKI Certificates

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SC-12(5) — PKI Certificates / Hardware Tokens

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SC-12(6) — Physical Control of Keys

Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.

Official discussion

For organizations that use external service providers (e.g., cloud service or data center providers), physical control of cryptographic keys provides additional assurance that information stored by such external providers is not subject to unauthorized disclosure or modification.

Assessment objectives and methods

physical control of cryptographic keys is maintained when stored information is encrypted by external service providers.

Examine

  • System and communications protection policy
  • procedures addressing cryptographic key establishment, management, and recovery
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibilities for cryptographic key establishment or management

Test

  • Mechanisms supporting and/or implementing cryptographic key establishment and management
Source record

Authoritative sources