Rule ID
SV-288245r1252945_rule
Version
V1R0.1
CCIs
CNSSP 15 specifies the use of public standards for cryptographic protocol and algorithm interoperability to protect National Security Systems (NSS). Based on National Security Memorandum (NSM)-10 and the threat of quantum computing on traditional public key cryptography, NSS must begin to transition to new algorithms for several cryptographic services that are the bedrock for cybersecurity assurances. The policy updates the set of authorized algorithms to provide quantum resistance, removing those that do not provide adequate security in a post-quantum ecosystem and replacing them with other standardized, widely available algorithms to ensure a strong cybersecurity posture into the future. CNSSP 15 Annex B contains a table of NIST cryptographic algorithms approved by NSA to protect NSS. This requirement pertains to Zero Trust.
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to generate cryptographic hashes. If the application's cryptography mechanism does not use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to generate cryptographic hashes, this is a finding.
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to generate cryptographic hashes.