PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SC-13 — Cryptographic Protection

Framework: NIST SP 800-53 Rev.5 SC-13 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Review documentation identifying each cryptographic use in the system (encryption in transit, at rest, hashing, signing, authentication) mapped to the approved algorithm and mode for that use.
Examine Confirm all deployed cryptographic modules are FIPS 140-2/140-3 validated (verify CMVP certificate numbers) or NSA-approved as required for the information's classification.
Test Inspect configurations to confirm only approved algorithms are enabled (e.g., AES-256, SHA-256+, RSA-2048+/ECC) and that deprecated algorithms (DES/3DES, MD5, SHA-1, RC4) are disabled.
Interview Ask personnel how they track algorithm deprecation and maintain crypto-agility (ability to replace algorithms) and how CMVP module validation status is monitored over time.
Examine Verify FIPS mode is enabled on operating systems and appliances where required (e.g., OS FIPS policy setting, appliance FIPS configuration).
Examine Confirm the strength of cryptographic protections aligns with the FIPS 199 categorization / data classification of the information being protected.