{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Cryptography & Key Management","Data Protection & Privacy","Network & Communications Security"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-weak-or-absent-encryption","description":"Sensitive data stored or transmitted without adequate encryption, or use of weak/flawed cryptography and poor key generation, storage, rotation, and destruction — enabling interception, disclosure, or tampering of data.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"crypto-weak-or-absent-encryption","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"id":"risk:crypto-weak-or-absent-encryption","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-weak-or-absent-encryption","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Weak or absent encryption and key management","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d7ed4cf34f1e7b868f597d323b1b8bd111160279bd908e186ab865856d550f4","properties":{"rationale":"protecting data in use (memory/session encryption, enclaves) extends cryptographic coverage to active data, closing the residual exposure that at-rest/in-transit encryption leaves open","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","sourceId":"uc:UC-CRYPTO-04","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:649e529c9a9818779f804d162b20c955e77fa360adabe1b6097b6c3ca4e46a95","properties":{"rationale":"Mandating encryption for remote/wireless/mobile transmission reduces unencrypted-in-transit exposure; storage and key management addressed elsewhere.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8970c33bddd154c3cef76c7c7d82e5a8d118c74e982d2ab08a338dc51797f3fa","properties":{"rationale":"Renders data at rest unreadable and encrypts data in transit with strong cryptography, directly closing the absent/inadequate-encryption exposure for stored and transmitted data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9e0dcc9ad8606060d3ecee93533a2fd7f927c579eb12fbcf5f9cb3843894a9f","properties":{"rationale":"Mandates approved algorithms/key lengths and independently validated modules while banning deprecated primitives (SSL/early TLS, SHA-1, RSA<2048), directly eliminating weak/flawed cryptography and poor key generation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aef05ff264d1c00746124128b03a9dbc953f055f07cb074fb999c0823b83c8a1","properties":{"rationale":"Governs key generation, HSM storage, rotation, and destruction under dual control, directly remediating the poor-key-management facet that weakens encryption.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"}],"schemaVersion":1}
