PAI-SF / 3 / PAI-SF-ATT-003
Attestation Key Custody
Objective
Protect attestation/signing keys from extraction or misuse.
Control / requirement
Keys held in hardware security module or secure element, never exposed to general-purpose compute.
Applicability
All systems relying on cryptographic attestation (ATT- 001, TEL-001).
Expected evidence
HSM configuration audit; key-extraction test attempts. [T2]
Assurance expectation
Test evidence of resistance to extraction attempts, not only configuration review.
Dependencies
Underlies PAI-SF-ATT-001 and PAI-SF-TEL-001 — both depend on key custody holding.
Exclusions
None — any system using cryptographic attestation depends on this control.
Maturity / conformance relevance
Expected at all conformance levels where attestation is used.
Ecosystem relationship
A single point of failure for both Domain 3 attestation and Domain 7 telemetry integrity if not held — flagged as a cross-domain dependency worth explicit tracking.