|
+CRY-14.01B |
1. ÜbersichtCRY-14.01BThe cloud service provider has documented and implemented procedures to deactivate cryptographic keys. These procedures ensure that:1. Expired keys are no longer used for encryption purposes, but may still be used for decryption if necessary; 2. Expired keys are no longer used for signature creation, but may still be used for signature verification; 3. Deactivated keys are eventually destroyed when they are no longer required, with relevant metadata retained for auditing; and 4. All actions related to key deactivation and destruction are recorded in the key management system to maintain a detailed audit log.
1.1 Referenzen1.2 Identifizierte Anforderungen1.2 Related Regulation2. Identifizierte Anforderungen
3. Related Regulations
|