Key Escrow
What is Key Escrow?
An arrangement in which cryptographic keys are held by a trusted third party (escrow agent) for later retrieval under defined conditions. Key escrow enables lawful access to encrypted data when the original key holder is unavailable.
Terms that appear alongside key escrow
Each of these is named in at least one of the same controls as key escrow. The number is how many controls name both.
- fips 4 shared controls
- nist 3 shared controls
- post quantum cryptography 2 shared controls
- audit trail 2 shared controls
- audit 2 shared controls
- chain of custody 2 shared controls
- availability 2 shared controls
- encryption 2 shared controls
Frameworks that govern key escrow
What the standards actually require on key escrow
Requirements naming key escrow across 6 standards, quoted from the control text.
Maintain availability of information in event of loss of cryptographic keys via key escrow or recovery; HIGH only.
SC-12(1) · Availability →Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...
X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records →Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).
SC-12 · Cryptographic Key Establishment and Management →ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) St...
ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS · ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM →Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).
SC-12 · Cryptographic Key Establishment and Management →Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).
SC-12 · Cryptographic Key Establishment and Management →Questions people ask about key escrow
What is Key Escrow?
Why is Key Escrow important for compliance?
Which compliance frameworks address Key Escrow?
Where can I learn more about Key Escrow?
See how Key Escrow applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.