Study. uk . com
  1. Home
  2. All questions
  3. Question 235

CISSP study material · question 235 of 500

A key with three months of its cryptoperiod remaining is found to have been exposed. An administrator proposes leaving it in service until the scheduled rotation. What does NIST SP 800-57 require?

  1. The cryptoperiod is unaffected; only the key's assurance level changes.
  2. The cryptoperiod is halved and the key retired at the new date.
  3. The cryptoperiod is no longer valid once the key is compromised, so the key must not remain in use.
  4. The cryptoperiod may run to its scheduled end provided the exposure is logged.
Show the answer

Answer: C. The cryptoperiod is no longer valid once the key is compromised, so the key must not remain in use.

SP 800-57 states that if a key is compromised its cryptoperiod shall no longer be considered valid, regardless of the time originally assigned to it.

Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 > 5.3 Cryptoperiods

Challenge yourself on this topic → Study as cards