Study. uk . com
  1. Home
  2. All questions
  3. Question 238

CISSP study material · question 238 of 500

An organisation uses approved algorithms at recommended key sizes. Which consideration does NIST SP 800-57 say usually drives cryptoperiod selection in that situation, and why?

  1. The physical, procedural and logical protection around the key, because subverting the system costs an attacker less than breaking the cipher.
  2. The volume of data, because approved algorithms fail only under load.
  3. The key size, because cryptanalysis remains the dominant threat at all sizes.
  4. The vendor's certification level, because validation governs how long a key may live.
Show the answer

Answer: A. The physical, procedural and logical protection around the key, because subverting the system costs an attacker less than breaking the cipher.

With strong cryptography in place, access protections drive the choice more than key size, since penetrating the system costs an attacker less than cryptanalysis.

Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 > 5.3.1 Factors Affecting Cryptoperiods

Challenge yourself on this topic → Study as cards