Skip to main content

Crypto / Key

Key Management Capabilities

Version: DEV

IDTitleDescriptionThreat Mappings
CCC.KeyMgmt.CP01AES-256Support for the AES-256 Advanced Encryption Standard with a 256-bit key for encryption and decryption.
0
CCC.KeyMgmt.CP02RSA-2048Supports the RSA algorithm with a key size of 2048 bits for encryption and digital signatures.
0
CCC.KeyMgmt.CP03RSA-3072Supports the RSA algorithm with a key size of 3072 bits for encryption and digital signatures.
0
CCC.KeyMgmt.CP04RSA-4096Supports the RSA algorithm with a key size of 4096 bits for encryption and digital signatures.
0
CCC.KeyMgmt.CP05EC-P256Supports the elliptic curve signing algorithm using the P-256 Curve for digital signatures.
0
CCC.KeyMgmt.CP06EC-P256KSupports the elliptic curve signing algorithm using the Secp256k1 Curve for digital signatures.
0
CCC.KeyMgmt.CP07EC-P384Supports the elliptic curve signing algorithm using the P-384 Curve for digital signatures.
0
CCC.KeyMgmt.CP08Key CreationSupports secure key creation within the key management service using the supported algorithms.
0
CCC.KeyMgmt.CP09Encrypt dataProvides the ability to securely encrypt data using a managed key in the supported encryption algorithms.
0
CCC.KeyMgmt.CP10Decrypt dataProvides the ability to securely decrypt data using a managed key in the supported encryption algorithms.
1
CCC.KeyMgmt.CP11Create Digital SignatureSupports the generation of a digital signature for data using the supported signing algorithms.
0
CCC.KeyMgmt.CP12Verify Digital SignatureSupports the verification of the digital signature of some data using the supported signing algorithms.
0
CCC.KeyMgmt.CP13Supports FIPS 140-2 Level 3Supports FIPS 140-2 Level 3 certified Hardware Security Modules (HSM).
0
CCC.KeyMgmt.CP14Key VersioningProvides the ability to manage multiple versions of a key.
1
CCC.KeyMgmt.CP15Key labelSupports the ability to tag a managed key with user defined labels.
0
CCC.KeyMgmt.CP16Disable keySupports the ability to disable a managed key without deletion.
1
CCC.KeyMgmt.CP17Enable keySupports the ability to re-enable a disabled managed key.
1
CCC.KeyMgmt.CP18Soft DeleteSupports the ability to prevent the immediate deletion of a managed key. This includes the ability to recover accidental deletion of keys within a grace period.
1
CCC.KeyMgmt.CP19Delete KeySupports the ability to permanently delete a managed key after the grace period defined on soft delete.
1
CCC.KeyMgmt.CP20Automatic Symmetric Key RotationSupports the ability to automatically rotate a managed symmetric key as long as the key was generated within the KMS.
1
CCC.KeyMgmt.CP21Manual Key RotationSupports the ability to manually rotate a managed key.
1
CCC.KeyMgmt.CP22Key ImportSupports the ability to import externally generated keys into the KMS.
1
CCC.KeyMgmt.CP23Key ExpirySupports the ability to set an expiration date for a key
0
CCC.KeyMgmt.CP24Key ReplicationSupports the ability to securely replicate a key across different regions using automated or manual process.
0

Imports

IDRemarks
CCC.Core.CP01Encryption in Transit Enabled by Default
CCC.Core.CP02Encryption at Rest Enabled by Default
CCC.Core.CP03Access Log Publication
CCC.Core.CP06Access Control
CCC.Core.CP07Event Publication
CCC.Core.CP08Data Replication
CCC.Core.CP09Metrics Publication
CCC.Core.CP10Log Publication
CCC.Core.CP14API Access
CCC.Core.F19Resource Scaling
CCC.Core.F28Command-line
CCC.Core.F29Active Ingestion