Skip to main content

CCC.KeyMgmt.C01: Alert on Key-version Changes

Control ID:CCC.KeyMgmt.C01
Title:Alert on Key-version Changes
Objective:Generate near-real-time alerts when a KMS key version is disabled or scheduled for deletion, enabling rapid investigation and recovery.
Control Family:
Logging and Metrics Publication

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.KeyMgmt.TH01Deletion or Disabling of Key Versions Causing Denial of Service or Data Loss Disabling, scheduling deletion, or permanently purging KMS key versions that protect sensitive data can prevent required decryption or signing operations. Service interruption or irreversible data loss may occur if the key material is no longer recoverable.
1
1
0

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.F14Key VersioningProvides the ability to manage multiple versions of a key.
CCC.KeyMgmt.F16Disable keySupports the ability to disable a managed key without deletion.
CCC.KeyMgmt.F18Soft DeleteSupports the ability to prevent the immediate deletion of a managed key. This includes the ability to recover accidental deletion of keys within a grace period.
CCC.KeyMgmt.F19Delete KeySupports the ability to permanently delete a managed key after the grace period defined on soft delete.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
RS.AN-1
0
Notifications from detection systems are investigated
NIST_800_53
IR-5
0
Incident Monitoring

Assessment Requirements

IDDescriptionApplicability
CCC.KeyMgmt.C01.TR01When a key version is scheduled for deletion or disabled, an alert MUST be generated within five minutes.
tlp-amber
tlp-red