Skip to main content

CCC.KeyMgmt.TH01: Deletion or Disabling of Key Versions Causing Denial of Service or Data Loss

Threat ID:CCC.KeyMgmt.TH01
Title:Deletion or Disabling of Key Versions Causing Denial of Service or Data Loss
Description:

Disabling, scheduling deletion, or permanently purging KMS key versions that protect sensitive data can prevent required decryption or signing operations. Service interruption or irreversible data loss may occur if the key material is no longer recoverable.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.CP14Key VersioningProvides the ability to manage multiple versions of a key.
CCC.KeyMgmt.CP16Disable keySupports the ability to disable a managed key without deletion.
CCC.KeyMgmt.CP18Soft DeleteSupports the ability to prevent the immediate deletion of a managed key. This includes the ability to recover accidental deletion of keys within a grace period.
CCC.KeyMgmt.CP19Delete KeySupports the ability to permanently delete a managed key after the grace period defined on soft delete.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1485
0
Data Destruction
MITRE-ATT&CK
T1489
0
Service Stop
MITRE-ATT&CK
T1490
0
Inhibit System Recovery

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.KeyMgmt.CN01Alert on Key-version ChangesGenerate near-real-time alerts when a KMS key version is disabled or scheduled for deletion, enabling rapid investigation and recovery. Logging and Metrics Publication
1
2
1