key management
termcryptographygovernance & risk
Generating, storing, rotating, revoking and retiring cryptographic keys - the part of cryptography that actually fails.
Algorithms are rarely broken in practice; keys are copied, checked into repositories, shared between environments, left on decommissioned hardware and never rotated because nobody knows what would break. The useful questions are therefore administrative: where does this key exist, who can use it, what happens the day it must be replaced, and has that ever been done. An organisation that cannot answer the last one has encryption whose strength is untested in the only way that matters.
Also known as: kms