The increasing use of cryptography in business applications has resulted in an increase in the number of keys used within an organisation. They need to be managed properly to ensure that key material does not fall into the wrong hands, and that keys with expiry dates are renewed before they expire and block access to your website or some other business critical system. This paper explains what is meant by key management, how to identify your keys, and how to protect them.