CEK-06: Are changes to cryptography-, encryption- and key management-related systems,
policies, and procedures, managed and adopted in a manner that fully accounts
for downstream effects of proposed changes, including residual risk, cost, and
benefits analysis?
Encryption change cost-benefit analysis is the process of comparing the benefit of encryption changes to its cost. a. Key change management cost-benefit analysis/return on investment (ROI) should be calculated for all key management-related changes. b. Every analysis should fully account for downstream effects of proposed changes, including residual risks. c. Every analysis should be reviewed and approved. d. Six months after a change, compare the anticipated ROI to the actual ROI. e. Significant deviation from the planned ROI should be audited. f. Report all audit results to the system authority.
Control implemented
Control ownership
Description
Manage and adopt changes to cryptography-, encryption-, and key management-related
systems (including policies and procedures) that fully account for downstream
effects of proposed changes, including residual risk, cost, and benefits analysis.