new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

key_management/recovery

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Compromise-recovery plan required contents

Compromise-recovery plan should contain: (1) Identification and contact info of personnel to notify, (2) Identification and contact info of personnel to perform recovery actions, (3) Re-key method, (4) Inventory of all cryptographic keys and their use (location of all certificates in system), (5) Education of appropriate personnel on recovery procedures, (6) Identification and contact info of personnel needed to support recovery procedures, (7) Policies that key-revocation checking be enforced to minimize compromise effect, (8) Monitoring of re-keying operations to ensure all required operations performed for affected keys.

Compromise-recovery additional procedures

Additional recovery procedures may include: (1) Physical inspection of equipment, (2) Identification of all information that may be compromised as result of incident, (3) Identification of all signatures that may be invalid due to compromise of signing key, (4) Distribution of new keying material if required.

Compromise-recovery plan documentation requirement

A compromise-recovery plan is essential for restoring cryptographic security services in event of key compromise. A compromise-recovery plan shall be documented and easily accessible.

Give your agent this brain