Skip to main content

CCC.KeyMgmt.TH03: Key Rotation is Disabled or Delayed Beyond Policy Limits

Threat ID:CCC.KeyMgmt.TH03
Title:Key Rotation is Disabled or Delayed Beyond Policy Limits
Description:

Modification of automatic or manual rotation settings can keep older key material active longer than intended, decreasing cryptographic resilience and extending exposure in the event of key compromise.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.F20Automatic Symmetric Key RotationSupports the ability to automatically rotate a managed symmetric key as long as the key was generated within the KMS.
CCC.KeyMgmt.F21Manual Key RotationSupports the ability to manually rotate a managed key.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1562
0
Impair Defenses

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.KeyMgmt.C03Enforce Automatic RotationEnsure symmetric keys rotate automatically within policy intervals to reduce exposure of key material. Key Lifecycle Management
1
2
1