- Home
- All questions
- Question 238
CISSP study material · question 238 of 500
An organisation uses approved algorithms at recommended key sizes. Which consideration does NIST SP 800-57 say usually drives cryptoperiod selection in that situation, and why?
Show the answer
Answer: A. The physical, procedural and logical protection around the key, because subverting the system costs an attacker less than breaking the cipher.
With strong cryptography in place, access protections drive the choice more than key size, since penetrating the system costs an attacker less than cryptanalysis.
Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 > 5.3.1 Factors Affecting Cryptoperiods