Skip to main content

Crypto / Key

Key Management Controls

Version: DEV

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.KeyMgmt.CN01Alert on Key-version ChangesGenerate near-real-time alerts when a KMS key version is disabled or scheduled for deletion, enabling rapid investigation and recovery.Observability
1
2
1
CCC.KeyMgmt.CN02Limit Decrypt PermissionsRestrict the Decrypt operation to authorised principals only, applying the principle of least privilege to protect sensitive data.Access
1
2
1
CCC.KeyMgmt.CN03Enforce Automatic RotationEnsure symmetric keys rotate automatically within policy intervals to reduce exposure of key material.Encryption
1
2
1
CCC.KeyMgmt.CN04Validate Imported KeysAccept only externally generated keys that meet approved cryptographic strength and provenance requirements.Encryption
1
2
1

Imports

IDRemarks
CCC.Core.CN01Prevent unencrypted requests
CCC.Core.CN02Ensure Data Encryption at Rest for All Stored Data
CCC.Core.CN03Implement multi-factor authentication (MFA) for access
CCC.Core.CN04Log all access and changes
CCC.Core.CN05Prevent access from untrusted entities
CCC.Core.CN06Prevent deployment in restricted regions
CCC.Core.CN10Prevent Data Replication to Destinations Outside Perimeter