Study. uk . com
  1. Home
  2. All questions
  3. Question 233

CISSP study material · question 233 of 500

A key management policy uses the word cryptoperiod without defining it. Which definition matches NIST SP 800-57 Part 1?

  1. The interval between the generation of a key and its escrow with a third party.
  2. The maximum time an adversary would need to recover the key by exhaustive search.
  3. The span of time during which a particular key is authorised for use by legitimate entities or remains in effect for a system.
  4. The time taken to distribute a new key to every node that will use it.
Show the answer

Answer: C. The span of time during which a particular key is authorised for use by legitimate entities or remains in effect for a system.

A cryptoperiod is the span in which a specific key is authorised for use by legitimate parties, or in which a system's keys remain in effect.

Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 > 5.3 Cryptoperiods

Challenge yourself on this topic → Study as cards