Skip to content

Move 1.3.4 "backup key access control" from L2 to L1 #29

@mperklin

Description

@mperklin

Section 1.3.4 has a L2 control that states:

The backup must be protected by access controls that prevent unauthorized parties from accessing it. Examples of this include safes, safe deposit boxes, or locked drawers where only the operator holds the key/combination for the lock.

This control should be moved to L1 alongside "Backup key exists."
Access controls for the backup key are an obvious requirement for L1.

A counterexample showing why this is necessary: it seems possible to have a backup key sitting on a desk and become L1 certified.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions