new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

key_management/backup

4 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Key backup capability for data at rest encryption

Data that has been encrypted with lost cryptographic keys will never be recovered. Therefore, it is essential that the application incorporate a secure key backup capability, especially for applications that support data at rest encryption for long-term data stores.

Key backup database encryption compliance

When backing up keys, ensure that the database used to store the keys is encrypted using at least a FIPS 140-2 or 140-3 validated module.

Key escrow considerations

It is sometimes useful to escrow key material for use in investigations and for re-provisioning of key material to users in the event that the key is lost or corrupted. Escrow is often performed by the Certificate Authority (CA) or key management system that provisions certificates and keys; however, in some instances separate APIs must be implemented.

Digital signature key escrow prohibition

Never escrow keys used for performing digital signatures, but consider the need to escrow keys that support encryption.

Give your agent this brain