SA-09.6 ยท Organization-controlled Cryptographic Keys

Control Description

Maintain exclusive control of cryptographic keys for encrypted material stored or transmitted through an external system.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
organization
Assurance
Enhancement
Control Statement
The control requirements

Maintain exclusive control of cryptographic keys for encrypted material stored or transmitted through an external system.

Supplemental Guidance

Maintaining exclusive control of cryptographic keys in an external system prevents decryption of organizational data by external system staff. Organizational control of cryptographic keys can be implemented by encrypting and decrypting data inside the organization as data is sent to and received from the external system or by employing a component that permits encryption and decryption functions to be local to the external system but allows exclusive organizational access to the encryption keys.

Related NIST Controls
Other NIST 800-53 controls related to this one