Skip to main content

Crypto / Key / Threats / DEV

Introduction of Weak or Compromised Key Material During Import

CCC.KeyMgmt.TH04

Insufficient validation during the key-import process may allow weak, back-doored, or otherwise compromised key material to be introduced, reducing the overall strength of subsequent cryptographic operations.

Related Capabilities

IDTitleDescription
CCC.KeyMgmt.CP22Key ImportSupports the ability to import externally generated keys into the KMS.

Related Controls

IDTitleDescription
CCC.KeyMgmt.CN04Validate Imported KeysAccept only externally generated keys that meet approved cryptographic strength and provenance requirements.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1600Weaken Encryption