| ID | Title | Objective | Control Family | Threat Mappings | Guideline Mappings | Assessment Requirements |
|---|---|---|---|---|---|---|
| CCC.KeyMgmt.CN01 | Alert on Key-version Changes | Generate near-real-time alerts when a KMS key version is disabled or scheduled for deletion, enabling rapid investigation and recovery. | Observability | 1 | 2 | 1 |
| CCC.KeyMgmt.CN02 | Limit Decrypt Permissions | Restrict the Decrypt operation to authorised principals only, applying the principle of least privilege to protect sensitive data. | Access | 1 | 2 | 1 |
| CCC.KeyMgmt.CN03 | Enforce Automatic Rotation | Ensure symmetric keys rotate automatically within policy intervals to reduce exposure of key material. | Encryption | 1 | 2 | 1 |
| CCC.KeyMgmt.CN04 | Validate Imported Keys | Accept only externally generated keys that meet approved cryptographic strength and provenance requirements. | Encryption | 1 | 2 | 1 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.CN01 | Prevent unencrypted requests |
| CCC.Core.CN02 | Ensure Data Encryption at Rest for All Stored Data |
| CCC.Core.CN03 | Implement multi-factor authentication (MFA) for access |
| CCC.Core.CN04 | Log all access and changes |
| CCC.Core.CN05 | Prevent access from untrusted entities |
| CCC.Core.CN06 | Prevent deployment in restricted regions |
| CCC.Core.CN10 | Prevent Data Replication to Destinations Outside Perimeter |