NIST SP 800-53 Rev 5
SC - System and Communications Protection

NIST SP 800-53 Rev 5 NIST800-SC-12: SC-12 Cryptographic Key Establishment and Management

Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 197 controls across 95 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 19 controls

  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.2 3.7.2 Secure distribution of cryptographic keys
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 3.7.4 3.7.4 Key changes at end of cryptoperiod
  • 3.7.5 3.7.5 Retirement, replacement or destruction of keys
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 3.7.9 3.7.9 Key guidance for service provider customers
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 3.7.1 3.7.1 Generation of strong cryptographic keys

CIS Controls v8 · 4 controls

  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.11 Encrypt Sensitive Data at Rest

SOC 2 · 4 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required
  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-DP-8 Ensure security of key and certificate repository

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 3 controls

  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-19 Certificate management
  • QRCM-1.2 Quantum-Vulnerable Identification
  • QRCM-3.1 Hybrid Solution Deployment (2025-2030)
  • QRCM-4.2 TLS 1.3 Adoption
  • SEC08-BP01 Implement secure key management
  • SEC09-BP01 Implement secure key and certificate management
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

C5 (Germany) · 2 controls

  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-04 Secure key management

CMMC 2.0 · 2 controls

  • CNSA2-INVENTORY Cryptographic Inventory and Discovery
  • CNSA2-KEM Key Establishment: ML-KEM-1024
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

FedRAMP High · 2 controls

  • AC-18(1) Authentication and Encryption
  • SC-12 Cryptographic Key Establishment and Management

FedRAMP Moderate · 2 controls

  • AC-18(1) Authentication and Encryption
  • SC-12 Cryptographic Key Establishment and Management

ISO 27701:2019 · 2 controls

  • 6.7 Cryptography
  • 6.7.1 Cryptographic controls

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption

NIST SP 800-187 · 2 controls

PTES · 2 controls

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • PTESPHASE-3 Threat Modeling
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • 4(g)(ii) Sec. 4(g)(ii) Meet FedRAMP key management requirements for access tokens and keys
  • 4(g)(iii) Sec. 4(g)(iii) Follow best practice for HSMs and isolation protecting cloud keys
  • US-ITAR-EAR-DS-01 Technical Data Protection
  • US-ITAR-EAR-DS-02 Cloud and Storage

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

ETSI EN 303 645 · 1 control

  • EN303645-5.4 Securely store sensitive security parameters
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

HIPAA Security Rule · 1 control

  • 62351-9 Cyber security key management

ISO 27001:2022 · 1 control

  • 8.24 Use of cryptography

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27011:2024 · 1 control

  • 27011-8.3 Cryptography and key management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NIS2 Directive · 1 control

  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • 03.13.10 Cryptographic Key Establishment and Management

NIST SP 800-190 · 1 control

  • SC-12 SC-12 Cryptographic Key Establishment and Management
  • SC-12 SC-12 Cryptographic Key Establishment and Management
  • SC-12 SC-12 Cryptographic Key Establishment and Management
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification

NIST SP 800-88 · 1 control

  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 1 control

  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI P2PE · 1 control

  • PCI-P2PE-09 Encryption and key management

PCI PIN Security · 1 control

  • PCI-PIN-09 Encryption and key management

PCI SSF · 1 control

  • PCI-SSF-09 Encryption and key management

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SHAREASSESS-3 Network Security, Endpoint, Data Protection

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SOC-CY-C2 Encryption and Data Protection

Saudi Arabia PDPL · 1 control

  • SA-PDPL-13 Encryption of personal data
  • SIGSTORE-3 Sigstore for Containers and Artifacts (Cosign)
  • IM8-CLD.2 Cloud Security Controls

South Korea ISMS-P · 1 control

  • ISMSP-SYS-02 Encryption Implementation

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TEXASTDPSA-2 Consumer Rights

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-2 Consumer Rights
  • VP-2 Holder Binding

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SC - System and Communications Protection

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-SC-12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 197 it maps to, and the evidence behind each claim, over MCP and REST.