new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

key_management/accountability

7 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Key accountability definition and purpose

Accountability involves identification of those that have access to, or control of, cryptographic keys throughout their lifecycles. Accountability can be an effective tool to help prevent key compromises and reduce the impact of compromises once detected.

Human key access accountability minimum requirement

Although it is preferred that no humans are able to view keys, as a minimum, the key management system should account for all individuals who are able to view plaintext cryptographic keys.

Advanced key access accountability tracking

More sophisticated key-management systems may account for all individuals authorized to access or control any cryptographic keys, whether in plaintext or ciphertext form.

Accountability benefits for key compromise

Accountability provides three significant advantages: (1) It aids in determination of when compromise could have occurred and what individuals could have been involved, (2) It protects against compromise because individuals with access know their access is known, (3) It is useful in recovering from detected key compromise to know where the key was used and what data or keys were protected.

Long-term human-controlled key accountability principles

Principles useful in enforcing accountability of cryptographic keys (may not apply to all systems or key types): (1) Uniquely identifying keys, (2) Identifying the key user, (3) Identifying dates and times of key use with protected data, (4) Identifying other keys protected by a symmetric or private key.

Key management audit types

Two types of audit should be performed on key management systems: (1) Security plan and procedures periodically audited to ensure they support the Key Management Policy (NIST SP 800-57 Part 2), (2) Protective mechanisms periodically reassessed regarding security level provided, future expectations, and correct/effective policy support.

Human action review frequency

On a more frequent basis, actions of humans who use, operate and maintain the system should be reviewed to verify they continue following established security procedures. Strong cryptographic systems can be compromised by lax and inappropriate human actions. Highly unusual events should be noted and reviewed as possible indicators of attempted attacks.

Give your agent this brain