unified
UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules
A cryptography standard defines approved algorithms, protocols, key lengths, and certificate profiles aligned to current industry guidance, and prohibits deprecated primitives (e.g., SSL/early TLS, SHA-1, RSA below 2048 bits). Cryptographic operations protecting sensitive data use independently validated cryptographic modules operating in approved modes. The standard is reviewed at least annually against emerging cryptanalytic and post-quantum developments.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Cryptography & Key Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CRYPTO-02
- title
- Use approved algorithms and validated cryptographic modules
- statement
- A cryptography standard defines approved algorithms, protocols, key lengths, and certificate profiles aligned to current industry guidance, and prohibits deprecated primitives (e.g., SSL/early TLS, SHA-1, RSA below 2048 bits). Cryptographic operations protecting sensitive data use independently validated cryptographic modules operating in approved modes. The standard is reviewed at least annually against emerging cryptanalytic and post-quantum developments.
- domain
- Cryptography & Key Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- IA-7
- coverage
- partial
- delta
- operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication)
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- SC-13
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.24
- coverage
- partial
- delta
- key management rules satisfied by the key lifecycle control
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules maps_to SC-13 — Cryptographic Protection
- framework
- nist-800-53
- control_id
- SC-13
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules
- UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- related
- rationale
- Banning early TLS and weak ciphers prevents protocol-downgrade and decryption of captured traffic, hardening the in-transit encryption that blocks interception.
- Cryptographic Key Management Review operates UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules
- UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules mitigates Compromised or counterfeit certificates / certificate authority
- strength
- related
- rationale
- Prohibiting SHA-1/weak keys and fixing certificate profiles raises the cryptanalytic cost of forging a certificate signature, an enabler of counterfeit certificates.
- UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules maps_to IA-7 — Cryptographic Module Authentication
- framework
- nist-800-53
- control_id
- IA-7
- coverage
- partial
- delta
- operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication)
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules maps_to A.8.24 — Use of cryptography
- framework
- iso-27001
- control_id
- A.8.24
- coverage
- partial
- delta
- key management rules satisfied by the key lifecycle control
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules mitigates Weak or absent encryption and key management
- strength
- primary
- rationale
- Mandates approved algorithms/key lengths and independently validated modules while banning deprecated primitives (SSL/early TLS, SHA-1, RSA<2048), directly eliminating weak/flawed cryptography and poor key generation.