CEK-01: Encryption and Key Management Policy and Procedures
Control Family:
Control is new to this version of the control set and incorporates the following items from the previous version: EKM-01: Entitlement, EKM-02: Key Generation, EKM-03: Sensitive Data Protection, GRM-06: Policy, GRM-09: Policy Reviews.
Control Statement
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.
Implementation Guidance
Policies and procedures on the use, protection, and lifetime of cryptographic keys should be developed and implemented through their full lifecycle. Policies and procedures include but are not limited to the following considerations: A. Policies and procedures relating to organization/management.
- Roles and responsibilities (See GRM for general considerations)
- Data protection (DSP domain for general considerations)
1) Data encryption 2) Algorithm
- Change management (See CCC domain for general considerations)
1) Cost-Benefit analysis
- Risk management (See BCR/GRC domains for general considerations)
- Monitoring and reporting (see LOG and monitoring domain for general considerations )
- Transaction/activity logging (see LOG and monitoring domain for general considerations)
- Incident handling (see SEF domain for general considerations)
- Audit (See A&A domain for general considerations)
B. Policies and procedures relating to key management.
- Key generation
- Key distribution
- Key rotation
- Key revocation
- Key destruction
- Key activation
- Key suspension
- Key deactivation
- Key archival
- Key compromise
- Key recovery
- Key inventory management
- Key purposes
- Key access
Auditing Guidance
- Review cryptography, encryption, and key management policy and procedures and confirm that these have been approved by appropriate management.
- Confirm that the policy and procedures are reviewed at least annually.
[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]
Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.