| name | IA-13(1)_protection-of-cryptographic-keys |
| description | Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse. |
| category | authentication |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","ia-13-1","ia","enhancement"] |
| tech_stack | ["aws","azure","active-directory","linux","windows"] |
| cwe_ids | ["CWE-287"] |
| chains_with | ["SC-12","SC-13"] |
| prerequisites | ["IA-13"] |
| severity_boost | {"SC-12":"Chain with SC-12 for comprehensive security coverage","SC-13":"Chain with SC-13 for comprehensive security coverage"} |
IA-13(1) Protection of Cryptographic Keys
Enhancement of: IA-13
High-Level Description
Family: Identification and Authentication (IA)
Framework: NIST SP 800-53 Rev 5
Identity assertions and access tokens are typically digitally signed. The private keys used to sign these assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.
What to Check
How to Test
Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for IA-13(1) implementation details. Verify the organization has documented how this control is satisfied.
Step 2: Validate Implementation
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Check authentication settings | cloud_audit_iam_policies |
| hackbrowser-mcp | Test authentication mechanisms | browser_auth_test |
Remediation Guide
Control Statement
Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.
Implementation Guidance
Identity assertions and access tokens are typically digitally signed. The private keys used to sign these assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.
Risk Assessment