SC-13 - Cryptographic Protection [FSv1.1]

This control is based on IBM Cloud Framework for Financial Services v1.1.

Control requirements

SC-13 - 0
The information system implements [IBM Assignment: the requirements in Supplemental Guidance for Cryptography Governance] in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

Additional IBM Cloud for Financial Services specifications

The organization must develop an overall cryptographic governance program that meets customer requirements and includes:

  • Security requirements for cryptographic hardware and software modules
  • Cryptographic key establishment and management requirements
  • Cryptographic key management technology and processes used to produce, control, and distribute symmetric and asymmetric cryptographic keys
  • Hash algorithms used
  • Random, pseudo-random, and prime number generator algorithms used
  • Cryptographic key sizes, operational lifecycles, storage, and distribution methods
  • Reliance on cryptographic services including certificate authorities (CA)

Implementation guidance

See the resources that follow to learn more about how to implement this control.

NIST supplemental guidance

Cryptography can be employed to support a variety of security solutions including, for example, the protection of classified and Controlled Unclassified Information, the provision of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances for such information but lack the necessary formal access approvals. Cryptography can also be used to support random number generation and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. This control does not impose any requirements on organizations to use cryptography. However, if cryptography is required based on the selection of other security controls, organizations define each type of cryptographic use and the type of cryptography required (e.g., protection of classified information: NSA-approved cryptography; provision of digital signatures: FIPS-validated cryptography).