REQ-WI-CRYPTO-01 — Cryptographic best practices
No sensitive data unencrypted at rest. Hardware-backed key stores. Industry-approved algorithms. Proper key management lifecycle.
| Property | Value |
|---|---|
| Section | TR 4.2.1 §5.7 |
Mapped Controls
| Control | Title |
|---|---|
| SID-CRYPTO-03 | AES-256-GCM Encrypted Keystore |
| SID-CRYPTO-02 | PRF Extension Key Derivation |
| SID-CRYPTO-05 | Secure Random Number Generation |
Source: Nordic EUDIW Common Certification System (NOBCCS) v0.4, June 2026