PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SC-12 — Cryptographic Key Establishment and Management

Framework: NIST SP 800-53 Rev.5 SC-12 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Review the cryptographic key management policy/procedures to confirm coverage of the full lifecycle: generation, distribution, storage, rotation, revocation, escrow/backup, and destruction.
Examine Confirm keys are generated with approved random sources and required key strengths, and that a current key/certificate inventory identifies each key's owner, purpose, and cryptoperiod (CIS Control 3.11).
Test Verify private keys and secrets are stored in a protected key store, vault, or FIPS 140-2/140-3 validated HSM rather than in cleartext files, source code, scripts, or configuration.
Interview Ask key custodians about access controls and whether dual control / split-knowledge and separation of duties are enforced for generating and using critical keys.
Examine Review key rotation and revocation records to confirm keys are rotated at defined cryptoperiods and are promptly revoked/replaced upon suspected compromise or custodian departure.
Examine Examine key destruction/zeroization records for retired keys and confirm that recovery keys are securely backed up or escrowed where continuity requires it.
Test Attempt to access the key store/vault or export a private key as an unauthorized user and confirm access is denied and the attempt is logged.