IA-13(1): Protection of Cryptographic Keys

CSF v2.0 References:

Threats Addressed:

Baselines:

(Not part of any baseline)

Info icon.

Control is new to this version of the control set.

Control Statement

Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.

Supplemental Guidance

Identity assertions and access tokens are typically digitally signed. The private keys used to sign these assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.