{"id":1850,"date":"2024-08-19T17:37:55","date_gmt":"2024-08-19T17:37:55","guid":{"rendered":"https:\/\/www.tarleton.edu\/security-controls-catalog\/?page_id=1850"},"modified":"2025-04-23T20:12:07","modified_gmt":"2025-04-23T20:12:07","slug":"sc-12-cryptographic-key-establishment-and-management","status":"publish","type":"page","link":"https:\/\/www.tarleton.edu\/security-controls-catalog\/system-and-communications-protection-sc\/sc-12-cryptographic-key-establishment-and-management\/","title":{"rendered":"SC-12: Cryptographic Key Establishment and Management"},"content":{"rendered":"\n<h1 class=\"wp-block-heading has-large-font-size\">SC-12: Cryptographic Key Establishment and Management<\/h1>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:16px\"><strong>NIST Baseline: <\/strong>Low&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:16px\"><strong>DIR Required By:<\/strong> &nbsp;01\/20\/2023&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:16px\"><strong>Review Date: \u00a0<\/strong>08\/08\/2024\u00a0<\/h2>\n\n\n\n<ul class=\"wp-block-list its-nested-list\">\n<li>The information resource owner, or designee, is responsible for:&nbsp;\n<ul class=\"wp-block-list\">\n<li>Managing cryptographic keys using automated mechanisms with supporting procedures where feasible.&nbsp;\n<ul class=\"wp-block-list\">\n<li>When automated mechanisms are not feasible, manual key management may be used along with sufficient supporting procedures and documentation.&nbsp;<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Appropriately securing public and private keys.&nbsp;<\/li>\n\n\n\n<li>Maintaining the availability of information in the event of the loss of cryptographic keys by users.&nbsp;\n<ul class=\"wp-block-list\">\n<li>Recovery of encryption keys should be part of business continuity planning except when data is only used by a single individual (e.g., a faculty member\u2019s grade book working copy).&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator alignfull has-text-color has-tarleton-purple-color has-alpha-channel-opacity has-tarleton-purple-background-color has-background is-style-wide\"\/>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\"><strong>References\/Additional Resources<\/strong><\/h3>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/fips\/140-3\/final\" target=\"_blank\" rel=\"noreferrer noopener\">FIPS 140-3<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/56\/a\/r3\/final\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-56A<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/56\/b\/r2\/final\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-56B<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/56\/c\/r2\/final\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-56C<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/57\/pt1\/r5\/final\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-57-1<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/57\/pt2\/r1\/final\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-57-2<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/57\/pt3\/r1\/final\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-57-3<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/63\/3\/upd2\/final\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-63-3<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/ir\/7956\/final\" target=\"_blank\" rel=\"noreferrer noopener\">IR 7956<\/a>&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/ir\/7966\/final\" target=\"_blank\" rel=\"noreferrer noopener\">IR 7966<\/a>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SC-12: Cryptographic Key Establishment and Management NIST Baseline: Low&nbsp; DIR Required By: &nbsp;01\/20\/2023&nbsp; Review Date: \u00a008\/08\/2024\u00a0 References\/Additional Resources FIPS 140-3&nbsp; SP 800-56A&nbsp; SP 800-56B&nbsp; SP 800-56C&nbsp; SP 800-57-1&nbsp; SP 800-57-2&nbsp; &#8230;<\/p>\n","protected":false},"author":1,"featured_media":580,"parent":1979,"menu_order":5,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"class_list":["post-1850","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"coauthors":[],"author_meta":{"author_link":"https:\/\/www.tarleton.edu\/security-controls-catalog\/author\/brian-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-3\/","display_name":"brian"},"relative_dates":{"created":"Posted 2 years ago","modified":"Updated 12 months ago"},"absolute_dates":{"created":"Posted on August 19, 2024","modified":"Updated on April 23, 2025"},"absolute_dates_time":{"created":"Posted on August 19, 2024 5:37 pm","modified":"Updated on April 23, 2025 8:12 pm"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/comments?post=1850"}],"version-history":[{"count":1,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1850\/revisions"}],"predecessor-version":[{"id":2656,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1850\/revisions\/2656"}],"up":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1979"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/media?parent=1850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}