CCC.KeyMgmt.C04: Validate Imported Keys
Control ID:CCC.KeyMgmt.C04
Title:Validate Imported Keys
Objective:Accept only externally generated keys that meet approved cryptographic strength and provenance requirements.
Control Family:
Key Lifecycle Management
Related Threats
ID | Title | Description | External Mappings | Capability Mappings | Control Mappings |
---|---|---|---|---|---|
CCC.KeyMgmt.TH04 | Introduction of Weak or Compromised Key Material During Import | Insufficient validation during the key-import process may allow weak, back-doored, or otherwise compromised key material to be introduced, reducing the overall strength of subsequent cryptographic operations. | 1 | 1 | 0 |
Related Capabilities
ID | Title | Description |
---|---|---|
CCC.KeyMgmt.F22 | Key Import | Supports the ability to import externally generated keys into the KMS. |