FedRAMP Controls / SC

SC-17 Public Key Infrastructure Certificates

Family SC
Baselines moderate
Mapped KSIs 1

Control statement

a. Issue public key certificates under an {{ insert: param, sc-17_odp }} or obtain public key certificates from an approved service provider; and
    b. Include only approved trust anchors in trust stores or certificate stores managed by the organization.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-SVC-06Secret Management
Automate management, protection, and regular rotation of digital keys, certificates, and other secrets.
Service Configuration