Skip to main content

Crypto / Key / Controls / DEV

Validate Imported Keys

CCC.KeyMgmt.CN04 · Encryption

Accept only externally generated keys that meet approved cryptographic strength and provenance requirements.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.CP22Key ImportSupports the ability to import externally generated keys into the KMS.

Related Threats

IDTitleDescription
CCC.KeyMgmt.TH04Introduction of Weak or Compromised Key Material During ImportInsufficient validation during the key-import process may allow weak, back-doored, or otherwise compromised key material to be introduced, reducing the overall strength of subsequent cryptographic operations.

Assessment Requirements

IDTextApplicability
CCC.KeyMgmt.CN04.AR01When a key import request is processed, the key MUST use an approved algorithm (RSA-2048+, EC-P256+) and originate from a certified HSM.tlp-green

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.DS-1Data at rest is protected
NIST_800_53SC-28Protection of Information at Rest