← Back to Baseline

MB-R182

HUMAN VERIFICATION REQUIRED ASVS 11.1.1 Key-management policy

MB-C15 ASVS Level 2 Human Assurance High

There is a documented policy for management of cryptographic keys and a cryptographic key lifecycle that follows a key management standard such as NIST SP 800-57. This should include ensuring that keys are not overshared (for example, with more than two entities for shared secrets and more than one entity for private keys).