Skip to main content

Crypto / Key

Key Management Controls

Version: DEV

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.KeyMgmt.CN01Alert on Key-version ChangesGenerate near-real-time alerts when a KMS key version is disabled or scheduled for deletion, enabling rapid investigation and recovery.Observability
1
2
1
CCC.KeyMgmt.CN02Limit Decrypt PermissionsRestrict the Decrypt operation to authorised principals only, applying the principle of least privilege to protect sensitive data.Access
1
2
1
CCC.KeyMgmt.CN03Enforce Automatic RotationEnsure symmetric keys rotate automatically within policy intervals to reduce exposure of key material.Encryption
1
2
1
CCC.KeyMgmt.CN04Validate Imported KeysAccept only externally generated keys that meet approved cryptographic strength and provenance requirements.Encryption
1
2
1