Agencies should cover at least the following in the KMP, as tabled in the control. Objectives: the aims of the cryptographic system and the KMP, organisational aims included, plus a reference to relevant NZCSIs. System description: the environment; the highest classification of information protected; topology diagrams with a description of the cryptographic system topology and its data flows; how keys are used; the key algorithm; key length; and key lifetime. Roles and administrative responsibilities: who does what, where relevant covering the COMSEC custodian, the cryptographic systems administrator, the record keeper, any cloud service provider, and the auditor. Accounting: how the cryptographic system is accounted for, which records are kept, and how those records are audited. Classification: of the hardware, the software and the documentation of the cryptographic system. Information security incidents: the conditions for declaring key material compromised, and references to the procedures for reporting and handling such incidents. Key management: the party that generates keys; how keys are delivered, received, distributed (local, remote and central), installed, transferred, stored, recovered, revoked and destroyed; logging of details on every access to key information or material; and approved access lists for cryptographic keys. Maintenance: upkeep of cryptographic system software and hardware, and destruction of equipment and media. References: vendor documentation and related policies.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.