CEK-18: Are processes, procedures, and technical measures to manage archived keys
in a secure repository (requiring least privilege access) being defined, implemented,
and evaluated to include legal and regulatory requirement provisions?
Key archiving places keys in long-term storage. a. Archived key material can support the later recovery of information. b. While archived key material may be needed in the future, the key material should be destroyed when no longer required. c. The key recovery process should include the generation, storage, and access of the long-term storage keys used to protect backed-up and archived key information. d. Archives should be used for long-term key access. e. The inventory system should record the storage and recovery of archived key information. f. All relevant transitions/activity should be recorded (logged) in the inventory management system (CKMS).
Control implemented
Control ownership
Description
Define, implement and evaluate processes, procedures and technical
measures to manage archived keys in a secure repository requiring least privilege
access, which include provisions for legal and regulatory requirements.