- Home
- All questions
- Question 235
CISSP study material · question 235 of 500
A key with three months of its cryptoperiod remaining is found to have been exposed. An administrator proposes leaving it in service until the scheduled rotation. What does NIST SP 800-57 require?
Show the answer
Answer: C. The cryptoperiod is no longer valid once the key is compromised, so the key must not remain in use.
SP 800-57 states that if a key is compromised its cryptoperiod shall no longer be considered valid, regardless of the time originally assigned to it.
Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 > 5.3 Cryptoperiods