Skip to main content

Crypto / Key / Controls / DEV

Enforce Automatic Rotation

CCC.KeyMgmt.CN03 · Encryption

Ensure symmetric keys rotate automatically within policy intervals to reduce exposure of key material.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.CP20Automatic Symmetric Key RotationSupports the ability to automatically rotate a managed symmetric key as long as the key was generated within the KMS.
CCC.KeyMgmt.CP21Manual Key RotationSupports the ability to manually rotate a managed key.

Related Threats

IDTitleDescription
CCC.KeyMgmt.TH03Key Rotation is Disabled or Delayed Beyond Policy LimitsModification of automatic or manual rotation settings can keep older key material active longer than intended, decreasing cryptographic resilience and extending exposure in the event of key compromise.

Assessment Requirements

IDTextApplicability
CCC.KeyMgmt.CN03.AR01When rotation settings are examined, rotation MUST be enabled with an interval not exceeding 365 days.tlp-green

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.DS-1Data at rest is protected
NIST_800_53SC-12Cryptographic Key Establishment and Management