Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Encryption key inventory and management system

Critical
High
Normal
Low

The Encryption Key Management System (CKMS) handles, manages, stores, and monitors encryption keys. The management system can be implemented as an automated tool or as a more manual implementation.

The organization must have the means to monitor and report on all encryption materials and their status using an encryption key management system. The cryptographic key management system should be used at least to:

  • Track changes to cryptographic states
  • Generate and distribute cryptographic keys
  • Generate public-key certificates
  • For monitoring unidentified encrypted assets
  • For cataloging, archiving, and backing up encryption keys
  • Maintains a database of connections to an organization's certificate and encryption key structures
Connected other frameworks and requirements:
10: Encryption
ISO 27017
10.1: Encryption management
ISO 27017
10.1.2: Key management
ISO 27017

Providing customers with encryption key management capabilities

Critical
High
Normal
Low

The service provider has to be able to offer the customer a possibility for independently controlling storage and management of encryption keys that are used for the data they manage.

Details for this division of labor should be mentioned in service level agreements, terms of use or other similar documents.

Connected other frameworks and requirements:
10: Encryption
ISO 27017
10.1: Encryption management
ISO 27017
10.1.2: Key management
ISO 27017

Monitoring management of encryption and encryption keys

Critical
High
Normal
Low

The organization must have the ability to monitor and report on actions related to encryption and encryption key management.

When abnormal activity is detected it must be handled in accordance with incident management processes.

Connected other frameworks and requirements:
10: Encryption
ISO 27017
10.1: Encryption management
ISO 27017
10.1.2: Key management
ISO 27017
No items found.