Skip to main content

CCC.KeyMgmt.TH04: Introduction of Weak or Compromised Key Material During Import

Threat ID:CCC.KeyMgmt.TH04
Title:Introduction of Weak or Compromised Key Material During Import
Description:

Insufficient validation during the key-import process may allow weak, back-doored, or otherwise compromised key material to be introduced, reducing the overall strength of subsequent cryptographic operations.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.F22Key ImportSupports the ability to import externally generated keys into the KMS.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1600
0
Weaken Encryption

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.KeyMgmt.C04Validate Imported KeysAccept only externally generated keys that meet approved cryptographic strength and provenance requirements. Key Lifecycle Management
1
2
1