NIST 800-53 Rev 5

424 controls available

CM-3(6)high

Cryptography Management

Configuration Management

Control Statement

Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: {{ insert: param, cm-03.06_odp }}.

Discussion

The controls referenced in the control enhancement refer to security and privacy controls from the control catalog. Regardless of the cryptographic mechanisms employed, processes and procedures are in place to manage those mechanisms. For example, if system components use certificates for identification and authentication, a process is implemented to address the expiration of those certificates.

Framework
NIST SP 800-53 Rev 5
Family
Configuration Management
Baselines
high

Related Frameworks

3 paths across 2 frameworks
SCF1 mapping
CHG-02.5Cryptographic Management
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI2 mappings
CCI-001745
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001746
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

103 STIGs reach this control through 49 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System - Server

35 STIGs
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-173 of 448 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-132 of 375 findings match
Show 27 more STIGs in this category →
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-191 of 103 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-191 of 216 findings match

Operating System - Mainframe

39 STIGs
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-091 of 225 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-091 of 222 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-091 of 230 findings match
Mainframe Product Security Requirements Guide
32024-12-051 of 193 findings match
Show 31 more STIGs in this category →
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match

Network Device

4 STIGs

Virtualization / Container

3 STIGs

Uncategorized

22 STIGs
Oracle Linux 9 Security Technical Implementation Guide
V1R62026-05-143 of 448 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R92026-05-142 of 376 findings match
Show 14 more STIGs in this category →
Application Layer Gateway Security Requirements Guide
V2R42026-05-231 of 160 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R92026-06-151 of 226 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R92026-06-031 of 223 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R92026-06-151 of 231 findings match
Mainframe Product Security Requirements Guide
V3R52026-05-231 of 194 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R62026-05-131 of 214 findings match
Virtual Machine Manager Security Requirements Guide
V2R42026-06-291 of 198 findings match