SC-28(3) - Protection of Information at Rest | Cryptographic Keys

Provide protected storage for cryptographic keys [Selection: [Assignment: organization-defined safeguards] ; hardware-protected key store].


ID: SC-28(3)
Enhancement of : SC-28

Space Segment Guidance

Encrypting data at rest protects mission secrets if the vehicle is lost or a memory chip is harvested during on-orbit servicing. Implement full-disk or partition encryption using an NSA-approved algorithm with keys stored only in volatile memory that clears on power loss. Load keys through a secure uplink session, wrap them with a master key burned in fuses and erase operational keys before disposal or deorbit. Ground operators can command a zero routine that scrubs both keys and decrypted data blocks, meeting national policy for end-of-life sanitization without requiring physical destruction.