Frameworks / NIST SP 800-53 Rev 5 / NIST800-SC-12 NIST SP 800-53 Rev 5
SC - System and Communications Protection
NIST SP 800-53 Rev 5 NIST800-SC-12: SC-12 Cryptographic Key Establishment and Management Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 197 controls across 95 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 2.3.2 2.3.2 Wireless encryption keys changed on triggers 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations 3.7.2 3.7.2 Secure distribution of cryptographic keys 3.7.3 3.7.3 Secure storage of cryptographic keys 3.7.4 3.7.4 Key changes at end of cryptoperiod 3.7.5 3.7.5 Retirement, replacement or destruction of keys 3.7.7 3.7.7 Prevent unauthorized substitution of keys 3.7.9 3.7.9 Key guidance for service provider customers 9.2.4 9.2.4 Locking of consoles in sensitive areas 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse 3.7.1 3.7.1 Generation of strong cryptographic keys CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.11 Encrypt Sensitive Data at Rest SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required ASBv3-DP-6 Use a secure key management process ASBv3-DP-8 Ensure security of key and certificate repository FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-19 Certificate management QRCM-1.2 Quantum-Vulnerable Identification QRCM-3.1 Hybrid Solution Deployment (2025-2030) QRCM-4.2 TLS 1.3 Adoption SEC08-BP01 Implement secure key management SEC09-BP01 Implement secure key and certificate management AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection C5-CRY-01 Policy for the use of encryption procedures and key management C5-CRY-04 Secure key management CNSA2-INVENTORY Cryptographic Inventory and Discovery CNSA2-KEM Key Establishment: ML-KEM-1024 CJIS-8 Media Protection CJIS-9 System and Communications Protection AC-18(1) Authentication and Encryption SC-12 Cryptographic Key Establishment and Management AC-18(1) Authentication and Encryption SC-12 Cryptographic Key Establishment and Management 6.7 Cryptography 6.7.1 Cryptographic controls ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption PTESPHASE-2 Intelligence Gathering (OSINT) PTESPHASE-3 Threat Modeling CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management 4(g)(ii) Sec. 4(g)(ii) Meet FedRAMP key management requirements for access tokens and keys 4(g)(iii) Sec. 4(g)(iii) Follow best practice for HSMs and isolation protecting cloud keys US-ITAR-EAR-DS-01 Technical Data Protection US-ITAR-EAR-DS-02 Cloud and Storage APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) BSI-08 Cryptographic protection of data EN303645-5.4 Securely store sensitive security parameters FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected 03.13.10 Cryptographic Key Establishment and Management SC-12 SC-12 Cryptographic Key Establishment and Management SC-12 SC-12 Cryptographic Key Establishment and Management SC-12 SC-12 Cryptographic Key Establishment and Management NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGOB-3 API Security Standards, mTLS, and Encryption ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-2 SCA Exemptions and Risk-Based Authentication NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SHAREASSESS-3 Network Security, Endpoint, Data Protection SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC-CY-C2 Encryption and Data Protection SA-PDPL-13 Encryption of personal data SIGSTORE-3 Sigstore for Containers and Artifacts (Cosign) IM8-CLD.2 Cloud Security Controls ISMSP-SYS-02 Encryption Implementation TAIWAN-2 Consent, Notice, Sensitive Data TEXASTDPSA-2 Consumer Rights URUGUAY-3 Sensitive Data, Health Data, Children VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-2 Consumer Rights Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SC - System and Communications Protection You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-SC-12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 197 it maps to, and the evidence behind each claim, over MCP and REST.