IA-13.1 ยท Protection of Cryptographic Keys

Control Description

Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
organization
Enhancement
Control Statement
The control requirements

Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.

Supplemental Guidance

Identity assertions and access tokens are typically digitally signed. The private keys used to sign these assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.

Related NIST Controls
Other NIST 800-53 controls related to this one