SSCP Systems Security Certified PractitionerCryptographyEasy
A security auditor is reviewing a company's data at rest encryption strategy. The auditor notes that a significant portion of sensitive PII (Personally Identifiable Information) is encrypted using a symmetric key that is stored on the same server as the encrypted data. Which of the following cryptographic best practices is being violated?
- AKey stretching
- BKey derivation
- CKey escrow
- DKey separation
Show answer & explanationAnswer & explanation
Correct answer: D. Key separation
Storing the encryption key on the same server as the encrypted data violates the principle of key separation, which dictates that keys should be stored separately from the data they protect to prevent single points of compromise.
Why the other options are wrong
- A. Key stretching is used to make brute-force attacks more difficult on passwords by increasing the time it takes to test each password, not directly related to key storage location.
- B. Key derivation is the process of generating cryptographic keys from a secret, such as a master key or password, not the storage of keys.
- C. Key escrow is the practice of holding a copy of cryptographic keys by a third party, which is not the issue here.
Key Separation
The cryptographic principle of storing encryption keys separately from the data they protect to prevent unauthorized access to both simultaneously.
- Enhances security by creating multiple points of failure for an attacker.
- Often involves hardware security modules (HSMs) or separate key management systems.
- Crucial for data at rest and data in transit encryption.
Memory trick: Keys and locks, never in the same box!