{
  "node_id": "nist-sp-800-152-key-management",
  "title": "A Profile for U.S. Federal Cryptographic Key Management Systems",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2015-10-01",
  "bluf": "This Profile for U.S. Federal Cryptographic Key Management Systems (FCKMSs) contains requirements for their design, implementation, procurement, installation, configuration, management, operation, and use by U.S. Federal organizations. It is intended to assist CKMS designers and implementers in selecting features, and to assist federal organizations and their contractors when procuring, installing, configuring, operating, and using FCKMSs. An FCKMS can be owned and operated by a federal organization or by a private contractor that provides key management services for federal organizations.\n\nThe core obligation is for agencies to adopt, adapt, and migrate their FCKMSs to comply with the Profile requirements over time, particularly when creating or procuring new systems or services. These requirements establish minimum security strengths and cryptographic module standards based on the information system impact-levels defined in FIPS 200: Low, Moderate, and High. The Profile specifies that information rated at a Low impact-level must be protected with at least 112 bits of security strength, Moderate with at least 128 bits, and High with at least 192 bits. It also mandates the use of FIPS 140-validated cryptographic modules at specific security levels corresponding to each impact level.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-200-minimum-security-requirements",
    "fips-199-security-categorization",
    "nist-sp-800-57-key-management",
    "nist-sp-800-131a-rev-2-crypto-transitions"
  ],
  "primary_citations_count": 7
}