Inadequate key and certificate management stymies compliance strategies
Manual management processes complicate compliance
Manual processes do not provide the logs and audit trails that streamline the auditing process. Instead, confusing manual practices force everyone involved to waste valuable time and resources assessing the situation. Worse, if auditors determine that poorly documented processes do not meet regulatory mandates, the company pays exponentially more in the way of expensive remediation efforts, fines and lost opportunities.
Poorly managed encryption assets undermine compliance efforts
Encryption keys provide powerful tools for securing regulated data, but anyone with access to the keys has free access to the data. Regulatory bodies such as PCI DSS have clarified that companies must implement secure key management processes. Most company’s manual key management practices fail to measure up:
- Keys have multiple access points
- Keystores passwords are not changed regularly
- The same password is used across multiple keystores
- Private key(s) are manually shared between administrators and applications
- Distribution policies are lax or unclear
- Private keys and passwords are not changed when admins leave the organization
- Expansive key and certificate volumes leave glaring gaps in coverage






