SAMMY UI is optimized for resolutions with a width 1024px and higher.
CSC Key Management Capability
CEK-08: Are CSPs providing CSCs with the capacity to manage their own data encryption keys?
Key management capability is the process of CSPs providing CSCs the capability to manage CSC-owned or generated encryption keys.
a. The CSC and CSP should agree on the definition and scope of CSC-managed keys and document this (shared responsibility) in the SLA, applicable contracts, policies, and procedures.
b. The CSP should allow the CSC to manage policies, procedures, and processes.
c. The CSP should empower the CSC to manage keys and data encryption keys.
d. The CSP should enable the CSC to manage key encryption keys or master keys used to encrypt data keys.
e. The CSP should allow the CSC to use the key management system (e.g., transactions, reporting, etc.).
f. Optionally, the CSC should supply CSC-generated master encryption keys using bring-your-own-key (BYOK) mechanisms per the SLA.
Control implemented
Control ownership
Description

CSPs must provide the capability for CSCs to manage their own data encryption keys.