Skip to main content

CCC.KeyMgmt.C02: Limit Decrypt Permissions

Control ID:CCC.KeyMgmt.C02
Title:Limit Decrypt Permissions
Objective:Restrict the Decrypt operation to authorised principals only, applying the principle of least privilege to protect sensitive data.
Control Family:
Identity and Access Management

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.KeyMgmt.TH02Unrestricted Use of a KMS Key to Decrypt DataMisconfigured permissions that allow broad invocation of the Decrypt API can expose plaintext data, enabling unintended disclosure or exfiltration of sensitive information.
1
1
0

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.F10Decrypt dataProvides the ability to securely decrypt data using a managed key in the supported encryption algorithms.
CCC.KeyMgmt.F17Enable keySupports the ability to re-enable a disabled managed key.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
PR.AC-4
0
Access to assets is managed
NIST_800_53
AC-6
0
Least Privilege

Assessment Requirements

IDDescriptionApplicability
CCC.KeyMgmt.C02.TR01When IAM roles and key policies are reviewed, Decrypt permission MUST be granted exclusively to documented authorised principals.
tlp-green