Study. uk . com
  1. Home
  2. All questions
  3. Question 240

CISSP study material · question 240 of 500

A control system's availability matters more than anything else, and its re-keying process has a history of failures. The security team wants to shorten cryptoperiods sharply because the data is sensitive. What does NIST SP 800-57 caution?

  1. Sensitivity always dominates, so the shortening should proceed.
  2. Cryptoperiods cannot be varied once the risk assessment is complete.
  3. A very short cryptoperiod can be counter-productive where denial of service is the paramount concern and re-keying is error-prone.
  4. Availability concerns are addressed by key escrow rather than by cryptoperiod length.
Show the answer

Answer: C. A very short cryptoperiod can be counter-productive where denial of service is the paramount concern and re-keying is error-prone.

SP 800-57 says short cryptoperiods may be counter-productive, particularly where denial of service is the paramount concern and there is significant potential for error in re-keying or derivation.

Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 > 5.3.2 Consequence Factors Affecting Cryptoperiods

Challenge yourself on this topic → Study as cards