Skip to main content

V1.6 — Cryptographic Architecture

Cryptographic Architecture: 4 L3 requirement(s). V1.6.1: Verify that there is an explicit policy for management of cryptographic keys and that a cryptographic key lifecycle foll... V1.6.2: Verify that consumers of cryptographic services protect key material and other secrets by using key vaults or API based ... V1.6.3: Verify that all keys and passwords are replaceable and are part of a well-defined process to re-encrypt sensitive data. ... and 1 more.

PropertyValue
SectionV1.6
Ownerplatform

Mapped Controls

ControlTitle
SID-CRYPTO-01PKCS#11 HSM Key Protection
SID-CRYPTO-02PRF Extension Key Derivation
SID-CRYPTO-03AES-256-GCM Encrypted Keystore
SID-CRYPTO-05Secure Random Number Generation

Source: OWASP Application Security Verification Standard 4.0.3