Skip to main content

Crypto / Secrets / Controls / DEV

Enforce Secret Replication Policies

CCC.SecMgmt.CN02 · Data

Ensure that secrets are replicated only to authorized locations as per organizational data residency and compliance requirements.

Related Capabilities

IDTitleDescription
CCC.Core.CP08Data ReplicationThe service automatically replicates data across multiple deployments simultaneously with parity, or may be configured to do so.
CCC.Core.CP22Location Lock-InThe service may be configured to restrict the deployment of child resources to specific geographic locations.
CCC.Core.CP21Resource ReplicationThe service may be configured to replicate child resources across multiple deployments.

Related Threats

IDTitleDescription
CCC.Core.TH03Deployment Region Network is UntrustedSystems are susceptible to unauthorized access or interception by actors with social or physical control over the network in which they are deployed. If the geopolitical status of the deployment network is untrusted, unstable, or insecure, this could result in a loss of confidentiality, integrity, or availability of the service and its data.
CCC.Core.TH04Data is Replicated to Untrusted or External LocationsSystems are susceptible to unauthorized access or interception by actors with political or physical control over the network in which they are deployed. Confidentiality may be impacted if the data is replicated to a network where the geopolitical status is untrusted, unstable, or insecure.

Assessment Requirements

IDTextApplicability
CCC.SecMgmt.CN02.AR01Attempt to retrieve a secret from an unauthorized region and verify that access is denied.tlp-red, tlp-amber

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.DS-5
NIST_800_53AC-3
NIST_800_53SC-7