• Allgemein

Key Custodian Agreement

Someone in your organization needs to be responsible for managing the encryption of your environment and accept the importance of that role. For this reason, PKI`s requirement 3.6.8 states: „The requirement for key cryptographic administrators to formally recognize that they understand and accept their key deposit responsibilities.“ If key directors sign a formal document stating that they understand and assume their responsibilities, there is a better chance for them to recognize their role. Their principal directors need to understand the seriousness of the work they have done and evaluators need to see it as a kind of recognition. If key administrators don`t run properly or safely, it will affect your entire organization, as it can lead to security vulnerabilities and injuries. Someone really needs to be responsible for managing the encryption of your environment. The people we usually identify as your key administrators. They have to sign a document – that signature can be electronic or written – but what we need is some recognition from these people, that they really understand the seriousness of the work they have done, and they understand all the policies and procedures and that they are good. The purpose and intent is to understand that these individuals really have the keys to your kingdom. Your work is, in my opinion, one of the most important tasks of your entourage. If they don`t do their job well or if they don`t do it right or safely, it could effectively lead to a compromise from those around you. We have all seen violations by organizations in the past. Important administrators are one of the most important tasks of your organization.

You are responsible for creating encryption keys, changing keys, restoring keys, turning on keys, distributing keys, managing keys and more. You manage all aspects of encryption in your environment. Key administrators have the keys to your kingdom. From an evaluation perspective, the Assessor will work with your human resources department to determine who is responsible for managing the keys. We will ask for an artifact in which they have read and understood their responsibilities as key administrators in your circle. Your email address will not be published. The required fields are marked with a score of .