Skip to main content

Controls

Version:
IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.KeyMgmt.CN01Alert on Key-version ChangesGenerate near-real-time alerts when a KMS key version is disabled or scheduled for deletion, enabling rapid investigation and recovery.Observability121
CCC.KeyMgmt.CN02Limit Decrypt PermissionsRestrict the Decrypt operation to authorised principals only, applying the principle of least privilege to protect sensitive data.Access121
CCC.KeyMgmt.CN03Enforce Automatic RotationEnsure symmetric keys rotate automatically within policy intervals to reduce exposure of key material.Encryption121
CCC.KeyMgmt.CN04Validate Imported KeysAccept only externally generated keys that meet approved cryptographic strength and provenance requirements.Encryption121

Imports

IDRemarks
CCC.Core.CN01Prevent unencrypted requests
CCC.Core.CN02Ensure Data Encryption at Rest for All Stored Data
CCC.Core.CN03Implement multi-factor authentication (MFA) for access
CCC.Core.CN04Log all access and changes
CCC.Core.CN05Prevent access from untrusted entities
CCC.Core.CN06Prevent deployment in restricted regions
CCC.Core.CN10Prevent Data Replication to Destinations Outside Perimeter