unified

UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules

A cryptography standard defines approved algorithms, protocols, key lengths, and certificate profiles aligned to current industry guidance, and prohibits deprecated primitives (e.g., SSL/early TLS, SHA-1, RSA below 2048 bits). Cryptographic operations protecting sensitive data use independently validated cryptographic modules operating in approved modes. The standard is reviewed at least annually against emerging cryptanalytic and post-quantum developments.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Cryptography & Key Management
type
preventive
category
technical

Details

unified_id
UC-CRYPTO-02
title
Use approved algorithms and validated cryptographic modules
statement
A cryptography standard defines approved algorithms, protocols, key lengths, and certificate profiles aligned to current industry guidance, and prohibits deprecated primitives (e.g., SSL/early TLS, SHA-1, RSA below 2048 bits). Cryptographic operations protecting sensitive data use independently validated cryptographic modules operating in approved modes. The standard is reviewed at least annually against emerging cryptanalytic and post-quantum developments.
domain
Cryptography & Key Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    IA-7
    coverage
    partial
    delta
    operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication)
    relationship
    intersects_with
  • framework
    nist-800-53
    control_id
    SC-13
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.24
    coverage
    partial
    delta
    key management rules satisfied by the key lifecycle control
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections