# SC-17 — Public Key Infrastructure Certificates

- **Control ID:** SC-17
- **Family:** [SC](/md/families/SC.md)
- **Baselines:** moderate, high
- **Enhancement of:** No content available.

## Description

Issue public key certificates under an \[assignment\] or obtain public key certificates from an approved service provider; and Include only approved trust anchors in trust stores or certificate stores managed by the organization.

## Discussion

Public key infrastructure (PKI) certificates are certificates with visibility external to organizational systems and certificates related to the internal operations of systems, such as application-specific time services. In cryptographic systems with a hierarchical structure, a trust anchor is an authoritative source (i.e., a certificate authority) for which trust is assumed and not derived. A root certificate for a PKI system is an example of a trust anchor. A trust store or certificate store maintains a list of trusted root certificates.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

No content available.

## Related controls

- [AU-10](/md/controls/AU-10.md)
- [IA-5](/md/controls/IA-5.md)
- [SC-12](/md/controls/SC-12.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
