1Overview
SC.L2-3.13.10 governs the keys that make cryptography work. It requires that cryptographic keys be established and managed for the cryptography employed in organizational systems, so that the encryption protecting CUI rests on keys that are properly generated, protected, and maintained. It is a one-point requirement and may be deferred on a plan of action.
Encryption is only as strong as the keys behind it. A key that is generated weakly, stored insecurely, shared carelessly, or never rotated undermines the cryptography it supports, no matter how strong the algorithm. This control requires that cryptographic keys be established, generated and distributed properly, and managed, protected, rotated, and retired over their life, wherever cryptography is employed. The two assessment objectives are establishing keys and managing them.
Establish and manage cryptographic keys for cryptography employed in organizational systems.
The requirement is to establish and manage cryptographic keys wherever cryptography is used. Establishing keys means generating and distributing them securely; managing them means protecting, rotating, and retiring them over their lifecycle. The assessment objectives correspond to these two: keys are established whenever cryptography is employed, and keys are managed whenever cryptography is employed. Proper key management is what keeps the encryption trustworthy.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.13.10 into two objectives: establish keys and manage keys.
Cryptographic keys are established whenever cryptography is employed. Keys are generated and distributed properly.
Cryptographic keys are managed whenever cryptography is employed. Keys are protected, rotated, and retired.
The two objectives are establishment and management. The common gap is at objective [b], where keys are generated but not protected, rotated, or retired, so a compromised or stale key persists. The assessor looks for keys both established and managed wherever cryptography is used.
3Failure Patterns
The failures are about keys that are poorly established or unmanaged.
Keys stored insecurely
Keys kept in the clear or alongside the data they protect are exposed. Protecting keys as part of management keeps them secure.
Keys never rotated or retired
Keys that are never changed or retired accumulate risk over time. Rotation and retirement are part of managing keys over their life.
Weak generation or distribution
Keys generated weakly or distributed insecurely undermine the cryptography from the start. Proper establishment produces trustworthy keys.
4Ownership
This is an IT and security-owned technical control.
| Role | Responsibility for this control |
|---|---|
| IT and security | Establishes and manages cryptographic keys over their lifecycle. Owns the key management evidence. |
| System administrator | Applies key protection, rotation, and retirement on systems. |
| Security or compliance lead | Confirms keys are established and managed wherever cryptography is used. |
5Tooling
The control is delivered by key management practices and systems.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Secure key generation and distribution | Keys established properly. |
| [b] | Key management system, rotation and retirement process | Keys protected, rotated, and retired. |
The caveat is that management has to cover the full lifecycle, protection, rotation, and retirement, wherever cryptography is used. Keys established well but never managed still degrade over time. The assessor examines establishment and management, so both objectives have to hold.
6Evidence
The satisfied version of 3.13.10 shows keys established and managed.
| Evidence | What it demonstrates |
|---|---|
| Key management procedures | Objectives [a], [b]. Keys established and managed. |
| Key protection and rotation records | Objective [b]. Keys protected, rotated, and retired. |
The evidence should show cryptographic keys established through secure generation and distribution and managed over their lifecycle. The key management procedures together with protection and rotation records are the clearest demonstration of the control.
Strong encryption with weak key management is weak encryption
The key is the secret the whole scheme depends on, so this control asks that cryptographic keys be established and managed wherever cryptography is used. Building proper key management is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.10. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.10[a] and 3.13.10[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov