risk

Weak or absent encryption and key management

Sensitive data stored or transmitted without adequate encryption, or use of weak/flawed cryptography and poor key generation, storage, rotation, and destruction — enabling interception, disclosure, or tampering of data.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

category
cyber_security
domain
  • Cryptography & Key Management
  • Data Protection & Privacy
  • Network & Communications Security
taxonomy
  • iso-27005-vulnerability
  • nist-800-30-threat-event
  • nist-privacy-risk
inherent_rating
high

Details

risk_id
crypto-weak-or-absent-encryption
category
cyber_security
likelihood
medium
impact
high
inherent_rating
high
treatment
mitigate
taxonomies
  • iso-27005-vulnerability
  • nist-800-30-threat-event
  • nist-privacy-risk

Source

No record-specific source URL is provided.

Connections