{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Cryptography & Key Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-02","description":"A cryptography standard defines approved algorithms, protocols, key lengths, and certificate profiles aligned to current industry guidance, and prohibits deprecated primitives (e.g., SSL/early TLS, SHA-1, RSA below 2048 bits). Cryptographic operations protecting sensitive data use independently validated cryptographic modules operating in approved modes. The standard is reviewed at least annually against emerging cryptanalytic and post-quantum developments.","details":{"control_category":"technical","control_type":"preventive","domain":"Cryptography & Key Management","guidance":[],"members":[{"control_id":"IA-7","coverage":"partial","delta":"operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication)","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"SC-13","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.24","coverage":"partial","delta":"key management rules satisfied by the key lifecycle control","framework":"iso-27001","relationship":"intersects_with"}],"statement":"A cryptography standard defines approved algorithms, protocols, key lengths, and certificate profiles aligned to current industry guidance, and prohibits deprecated primitives (e.g., SSL/early TLS, SHA-1, RSA below 2048 bits). Cryptographic operations protecting sensitive data use independently validated cryptographic modules operating in approved modes. The standard is reviewed at least annually against emerging cryptanalytic and post-quantum developments.","title":"Use approved algorithms and validated cryptographic modules","unified_id":"UC-CRYPTO-02"},"id":"uc:UC-CRYPTO-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-02","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:115222064c136d9bc448cfd5f68724d78ed7d13912b19fb3d73b2e81be7b81f8","properties":{"control_id":"SC-13","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-13-d7da2f08.json","targetId":"ctrl:nist-800-53:SC-13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:12bd301f87985b8dcf439c7d65320d136f8fc8045ae1fb3adddaee347f98000d","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","targetId":"uc:UC-CRYPTO-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3d3f990630e2782c8aa78860c8fe6e41b33953c4c3f847c4749757ca140c724b","properties":{"rationale":"Banning early TLS and weak ciphers prevents protocol-downgrade and decryption of captured traffic, hardening the in-transit encryption that blocks interception.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41028e6a12818f87ff90dc730bd26db7d7757f5249270ece920529d42ce751fd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c18-ca9e8eba.json","sourceId":"wf:C18","targetDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","targetId":"uc:UC-CRYPTO-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d1f1a0ebca6eba2d224e2dc8357c03b7ae28e3d8419472daabcf58d915afb05","properties":{"rationale":"Prohibiting SHA-1/weak keys and fixing certificate profiles raises the cryptanalytic cost of forging a certificate signature, an enabler of counterfeit certificates.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/risk-crypto-counterfeit-certificates-d9dcc5c5.json","targetId":"risk:crypto-counterfeit-certificates","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:752fd17b5836191d0a944ca8edb24c2a98e3f970900367018fabf1c5575db95d","properties":{"control_id":"IA-7","coverage":"partial","delta":"operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication)","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-7-7dfc5b71.json","targetId":"ctrl:nist-800-53:IA-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ef2495e9d51f5cb612c76956abcf730d28d1dd358d8c4550b86b46566054d78","properties":{"control_id":"A.8.24","coverage":"partial","delta":"key management rules satisfied by the key lifecycle control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-24-f5cc6274.json","targetId":"ctrl:iso-27001:A.8.24","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9e0dcc9ad8606060d3ecee93533a2fd7f927c579eb12fbcf5f9cb3843894a9f","properties":{"rationale":"Mandates approved algorithms/key lengths and independently validated modules while banning deprecated primitives (SSL/early TLS, SHA-1, RSA<2048), directly eliminating weak/flawed cryptography and poor key generation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"}],"schemaVersion":1}
