Skip to main content

Crypto / Key

Controls

Version:
IDTitleObjective
CCC.KeyMgmt.CN01Alert on Key-version ChangesGenerate near-real-time alerts when a KMS key version is disabled or scheduled for deletion, enabling rapid investigation and recovery.
CCC.KeyMgmt.CN02Limit Decrypt PermissionsRestrict the Decrypt operation to authorised principals only, applying the principle of least privilege to protect sensitive data.
CCC.KeyMgmt.CN03Enforce Automatic RotationEnsure symmetric keys rotate automatically within policy intervals to reduce exposure of key material.
CCC.KeyMgmt.CN04Validate Imported KeysAccept only externally generated keys that meet approved cryptographic strength and provenance requirements.