Skip to main content

Core / Ccc / Threats / DEV

Encryption Key is Misused

CCC.Core.TH18

Encryption keys may be used by an unauthorized entity due to inadequate key management practices or the compromise of a connected system. This could lead to the decryption of sensitive data, impacting its confidentiality and integrity.

Related Capabilities

IDTitleDescription
CCC.Core.CP01Encryption in Transit Enabled by DefaultThe service automatically encrypts all data using industry-standard cryptographic protocols prior to transmission via a network interface.
CCC.Core.CP02Encryption at Rest Enabled by DefaultThe service automatically encrypts all data using industry-standard cryptographic protocols prior to being written to a storage medium.

Related Controls

IDTitleDescription
CCC.Core.CN13Minimize Lifetime of Encryption and Authentication CertificatesEnsure that encryption and authentication certificates have a limited lifetime to reduce the risk of compromise and ensure the use of up-to-date security practices.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1555.006Credentials from Password Stores: Cloud Secrets Management Stores