Study. uk . com
  1. Home
  2. All questions
  3. Question 239

CISSP study material · question 239 of 500

An architect proposes the same cryptoperiod for the keys protecting a message channel and the keys protecting a 40-terabyte archive. Why does NIST SP 800-57 treat these differently?

  1. Storage keys are exempt from cryptoperiods where the media is encrypted at rest.
  2. Storage keys usually get shorter cryptoperiods because archived data stays sensitive longer.
  3. Communication keys have no cryptoperiod, since sessions are ephemeral.
  4. Storage keys usually get longer cryptoperiods because rotating one means decrypting and re-encrypting everything it covered.
Show the answer

Answer: D. Storage keys usually get longer cryptoperiods because rotating one means decrypting and re-encrypting everything it covered.

SP 800-57 notes keys protecting communications often have shorter cryptoperiods than storage keys, because generating new keys and re-encrypting all the stored data is burdensome.

Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 > 5.3.3.1 Communications versus Storage

Challenge yourself on this topic → Study as cards