Skip to main content

Crypto / Key / Threats / DEV

Key Rotation is Disabled or Delayed Beyond Policy Limits

CCC.KeyMgmt.TH03

Modification of automatic or manual rotation settings can keep older key material active longer than intended, decreasing cryptographic resilience and extending exposure in the event of key compromise.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.CP20Automatic Symmetric Key RotationSupports the ability to automatically rotate a managed symmetric key as long as the key was generated within the KMS.
CCC.KeyMgmt.CP21Manual Key RotationSupports the ability to manually rotate a managed key.

Related Controls

IDTitleDescription
CCC.KeyMgmt.CN03Enforce Automatic RotationEnsure symmetric keys rotate automatically within policy intervals to reduce exposure of key material.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1562Impair Defenses