What A Profile for U.S. Federal Cryptographic Key Management Systems requires
This Profile for U.S. Federal Cryptographic Key Management Systems (FCKMSs) contains requirements for their design, implementation, procurement, installation, configuration, management, operation, and use by U.S. Federal organizations. It is intended to assist CKMS designers and implementers in selecting features, and to assist federal organizations and their contractors when procuring, installing, configuring, operating, and using FCKMSs. An FCKMS can be owned and operated by a federal organization or by a private contractor that provides key management services for federal organizations. The core obligation is for agencies to adopt, adapt, and migrate their FCKMSs to comply with the Profile requirements over time, particularly when creating or procuring new systems or services. These requirements establish minimum security strengths and cryptographic module standards based on the information system impact-levels defined in FIPS 200: Low, Moderate, and High. The Profile specifies that information rated at a Low impact-level must be protected with at least 112 bits of security strength, Moderate with at least 128 bits, and High with at least 192 bits. It also mandates the use of FIPS 140-validated cryptographic modules at specific security levels corresponding to each impact level.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-152.pdf
SHA-256 integrity: 0c31ad15a07f7a22662a45a6df48b46e564537fc192c622c781fb20ba7c10c3b
Primary Citations — 7 traced to source
- PR:2.2: A Federal CKMS shall support NIST-approved cryptographic algorithms, key-establishment schemes and modes of operation (as needed) in accordance with [SP 800-131A].
- PR:2.3: In a Federal CKMS, information (including loaded code and parameters) rated at a Low impact-level shall be protected with cryptographic algorithms and keys that provide at least 112 bits of security strength.
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/nist-sp-800-152-key-management.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/nist-sp-800-152-key-management.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/nist-sp-800-152-key-management
- Back to registry: Browse all 10,108 compliance nodes