Cybersecurity GRC 14 items
PKI & Certificate Lifecycle Management
Assesses public key infrastructure and certificate lifecycle governance covering CA security, issuance, inventory, renewal automation, and revocation.
NIST 800-57CA/Browser ForumNIST 800-53
Free PDF · enter your email to download.
CA Governance & Security
- Is the offline root CA kept air-gapped and physically secured? *
- Are CA private keys protected in an HSM meeting FIPS 140-2/3 Level 3? *
- Is a Certificate Policy (CP) and Certification Practice Statement (CPS) documented and maintained? *
- Are CA administrator roles separated with dual control for sensitive operations? *
Issuance & Policy
- Are certificate templates restricted to approved key usages and validity periods? *
- Do TLS certificates conform to CA/Browser Forum baseline requirements (max validity, key size)? *
- Is domain/identity validation enforced before certificate issuance? *
- Are weak algorithms (SHA-1, RSA <2048, deprecated curves) prohibited? *
Inventory & Renewal
- Is a complete inventory of issued certificates maintained with owners and expiry dates? *
- Are expiry alerts and automated renewal (e.g., ACME) used to prevent outages? *
- Are private keys generated and stored securely, never shared across systems? *
Revocation & Monitoring
- Are CRL and/or OCSP services available and monitored for freshness? *
- Is there a documented, tested process to revoke compromised certificates promptly? *
- Is Certificate Transparency monitored to detect mis-issued certificates for owned domains?
Download the full PKI & Certificate Lifecycle Management checklist
Get it as a clean, printable PDF — free.
