Skip to main content

Crypto / Key / Threats / DEV

Unrestricted Use of a KMS Key to Decrypt Data

CCC.KeyMgmt.TH02

Misconfigured permissions that allow broad invocation of the Decrypt API can expose plaintext data, enabling unintended disclosure or exfiltration of sensitive information.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.CP10Decrypt dataProvides the ability to securely decrypt data using a managed key in the supported encryption algorithms.
CCC.KeyMgmt.CP17Enable keySupports the ability to re-enable a disabled managed key.

Related Controls

IDTitleDescription
CCC.KeyMgmt.CN02Limit Decrypt PermissionsRestrict the Decrypt operation to authorised principals only, applying the principle of least privilege to protect sensitive data.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1550Use Alternate Authentication Material