DI-MISC-81688A
Key and Certificate Management Plan (KCMP)
The Key and Certificate Management Plan (KCMP) describes the use and control of cryptographic products and services used by a cryptographic application throughout its lifetime and the capabilities it requires from the key management infrastructure.
Approval DateJanuary 10, 2017
AMSC Number9760
Preparing ActivityNS/I21/I213
Project NumberMISC-2017-001
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Key and Certificate Management Plan (KCMP) describes the use and control of cryptographic products and services used by a cryptographic application (cryptographic engine, cryptographic module, End Cryptographic Unit (ECU), or system) throughout its lifetime. The KCMP also identifies and documents the capabilities that the cryptographic application requires from the current and planned key management infrastructure.
a. KCMP Related Guidance. As the vendor of a cryptographic application may have very little insight into the items in the KCMP, the Information Assurance Certification Manager (IACM) will ensure the vendor uses the KCMP Template included as part of this DID and has the applicable Telecommunications Security Requirements Document (TSRD) cited under "Reference Documents." The TSRD is intended for use with the KCMP template to detail other related and relevant information not covered here.
b. This Data Item Description (DID) contains the content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract, as the Key and Certificate Management Plan (KCMP).
c. This DID supersedes DI-MISC-81688.
Preparation Instructions
1Reference Documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1National Security Agency/Central Security Service (NSA/CSS) Policy Manual 1-52
1.2Telecommunications Security Requirements (TSRD) Commercial Communications Security (COMSEC) Evaluation Program (CCEP), Section 2.9
1.3TSRD User Participation Program (UPP), Section 2.9
1.4Information Assurance Directorate (IAD) Management Directive 110 ("Cryptographic Key Protection")
1.5Key and Certificate Management Plan (KCMP) Template, Version 1.0
1.6CNSSI No. 4001, "Controlled Cryptographic Items (CCI)"
1.7CNSSI No. 4031, "Cryptographic High Value Products (CHVP)"
1.8CNSSI No. 4003, "Reporting and Evaluating COMSEC Incidents"
2.1Be formatted strictly in accordance with the KCMP Template established for this purpose and that is referenced in paragraph 1.5 of this DID, under the "Reference Documents" section.
2.2Be appropriately classified and portion marked in accordance with National Security Agency/Central Security Service (NSA/CSS) Policy Manual 1-52.
2.3Be submitted in either Microsoft Word or Adobe PDF format.Adobe PDF format is preferred as it supports more efficient tracking and management of changes.
2.4Not contain embedded files (i.e., Microsoft Visio drawings).All pictures and diagrams must be converted to a JPG or similar format.
2.5Include a title page that minimally identifies the following:
2.5.3Contract Data Requirements List (CDRL) number
2.5.5Program Manager's name and telephone number and, if applicable, the NSA IACM's name and office designator
2.6Include a Revision Page, listing all past changes to the document in reverse chronological order.
2.7Include a list of Reference Documents.This would include all documents used to develop the KCMP, approved key specifications used by the cryptographic application, and any special exceptions/waivers granted to the program.
2.8Include a Table of Contents.
2.9Include a Table defining all abbreviations and acronyms.
2.10Total page count for the KCMP should not exceed 30 pages, with font size and type 12 Times New Roman.NSA reserves the right to return KCMPs numbering 30 or more pages with instructions to make them more concise and readable.
3.1Be completed using the Key and Certificate Management Plan (KCMP) Template, Version 1.0, included in this DID.NOTE: Not all requested information will apply.
3.2Contain only that information specifically requested.Including other information not specifically requested will lengthen the review time and consequently the approval of the KCMP.
4The Key and Certificate Management Plan Template, Version 1.0, follows on the next page.
Figures

Figure Table 1. Table 1. Abbreviations and Acronyms

Figure Table 2. Table 2. Key Management Products and Services Requirements
Schema v3.0Community-maintained · Verify against ASSIST