Skip to main content

CCC.KeyMgmt.C03: Enforce Automatic Rotation

Control ID:CCC.KeyMgmt.C03
Title:Enforce Automatic Rotation
Objective:Ensure symmetric keys rotate automatically within policy intervals to reduce exposure of key material.
Control Family:
Key Lifecycle Management

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.KeyMgmt.TH03Key Rotation is Disabled or Delayed Beyond Policy LimitsModification of automatic or manual rotation settings can keep older key material active longer than intended, decreasing cryptographic resilience and extending exposure in the event of key compromise.
1
1
0

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.F20Automatic Symmetric Key RotationSupports the ability to automatically rotate a managed symmetric key as long as the key was generated within the KMS.
CCC.KeyMgmt.F21Manual Key RotationSupports the ability to manually rotate a managed key.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
PR.DS-1
0
Data at rest is protected
NIST_800_53
SC-12
0
Cryptographic Key Establishment and Management

Assessment Requirements

IDDescriptionApplicability
CCC.KeyMgmt.C03.TR01When rotation settings are examined, rotation MUST be enabled with an interval not exceeding 365 days.
tlp-green