Skip to main content

Networking / Loadbalancer / Controls / DEV

Automate Certificate Renewal

CCC.LB.CN08 · Encryption

Maintain valid TLS certificates by automating renewal and deployment before expiry.

Related Capabilities

IDTitleDescription
CCC.LB.CP11SSL/TLS TerminationProcess of decrypting SSL or TLS encrypted traffic at the load balancer level rather than at the backend servers. This allows the load balancer to offload the decryption task from the backend servers.

Related Threats

IDTitleDescription
CCC.LB.TH07TLS Certificates Are Expired or InvalidStale or untrusted certificates weaken encrypted-traffic protection.

Assessment Requirements

IDTextApplicability
CCC.LB.CN08.AR01When a certificate is within 30 days of expiry, automated renewal MUST complete and deploy a new certificate within 24 hours.tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.DS-6Integrity checking mechanisms are used
NIST_800_53SC-17PKI certificates