
be well documented, and all copies of the key should be managed
carefully.
16.3.4 Exporting a key
Exporting a key from a secure management system is not recom-
mended because the system will have no means of verifying how
the key is used once it leaves the secure environment. If key export is
a requirement, exported copies of the key should be managed
carefully.
16.3.5 Rotating keys
It is good practice to protect data with newly generated keys period-
ically. Re-encrypting data with a new key at least once a year is
recommended. An important consideration when rotating keys is
managing backups and archives. An enterprise must be able to
ensure that sensitive ...