Rule ID
SV-288246r1252946_rule
Version
V1R0.1
CCIs
Use of improperly configured or lower-assurance equipment and solutions could compromise high-value information. CNSA 2.0 is the NSA's next-generation cybersecurity standard designed to protect National Security Systems (NSS) from the impending threat of quantum computing. It phases out vulnerable legacy algorithms (like RSA and ECC) in favor of quantum-resistant post-quantum cryptography (PQC) selected from NIST standards. This requirement pertains to Zero Trust.
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses CNSA 2.0 cryptographic algorithms. If the application's cryptography mechanism does not use CNSA 2.0 cryptographic algorithms, this is a finding.
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use CNSA 2.0 cryptographic algorithms.