HomeControl Library › 3.13.10
3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.10 — Manage your encryption keys

Establish and manage cryptographic keys for cryptography employed in organizational systems.

If you use encryption, you need a real process for creating, storing, rotating, and retiring the keys.

What it actually means

Encryption is only as strong as its key management. Establish and manage cryptographic keys: generate them properly, store them securely, control who can access them, and rotate or retire them. For small shops this often means leaning on managed services — your cloud KMS, BitLocker or FileVault recovery-key escrow — and documenting how keys are handled.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library