PlumbTrackLive demoGRC Risk System

← control library

Public Key Infrastructure Certificates SC-17

System and Communications Protection · Moderate baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SC-17 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Communications Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SC-17 (Public Key Infrastructure Certificates) is about managing the certificates and trust anchors your systems rely on. PKI (Public Key Infrastructure) is the system of certificates, keys, and authorities that lets machines prove who they are and set up encrypted connections. The control has two parts: issue certificates under a written certificate policy (or obtain them from an approved provider), and keep only approved trust anchors in the stores your organization manages. A trust anchor is a Certificate Authority (CA) — an issuer your system trusts by default, at the top of a chain of trust. It is a Moderate-baseline control.

What good looks like

Framework mapping

How to move it toward Implemented