Start with the property requiring protection
In a fictional financial-document service, encryption protects confidentiality, but the design also needs recovery and integrity. Ask who can read plaintext, who can change access policy, and who can verify a copy. An administrator with volume access and decryption permission can still read data even when the disk is encrypted. For a file and its hash, also protect the comparison reference. If the same identity can replace both without control, comparison may confirm a modified pair. Specify the property and adversary being considered before choosing evidence.
Separate new use from historical recovery
When an application moves from K1 to K2, define whether the change affects only new files or also existing data. Archives still encrypted exclusively with K1 need an authorized recovery path while required. Inventory identifiers, versions, owners, and dependencies. Retiring a key from active use does not automatically mean destroying it. In the specific AWS KMS example, rotating KMS key material neither re-encrypts data nor replaces data keys. An exposed data key therefore requires analysis of protected data, existing copies, and treatment options.
Distinguish technical threshold from authorization
In the synthetic 3-of-5 model, three distinct shares permit key reconstruction. Two unavailable people leave three available, but that proves only the arithmetic threshold under the stated assumptions. It establishes neither authorization for actual recovery nor functioning of other components. If a local rule also requires data-owner approval, that condition remains. Counting two accounts belonging to one person does not satisfy a requirement for two distinct people. Likewise, copying one share does not create another independent share. Custody should make people, material, and decisions visible without placing secrets in training records.
Design for the failure that matters
Five shares do not guarantee recovery after any site loss. If three are in A and two in B, losing A leaves only two, below the threshold of three. The same analysis applies to HSMs in different racks sharing cooling: losing one power supply does not test prolonged room loss. Map dependencies by event and check what remains available. In a simplified calculation of independent serial components, 0.99 × 0.99 × 0.98 gives 96.0498%. Their average does not represent simultaneous need, and independence needs evidence before the model can represent a real service.
Address exposure and trust
A renewed certificate using the same exposed private key does not erase knowledge of that key. A mathematically valid signature also does not by itself resolve a period of signing-key compromise. Response needs to scope affected material, configured trust, and artifacts potentially produced without authorization. Avoid promising that a local change erases copies already obtained by others. Plan transition with recovery and continuity while retaining evidence. If a cache permits use for twenty minutes and policy requires revocation within five, an architectural trade-off needs explicit resolution.
Guided practice: losing a site
Use the synthetic distribution below. For loss of A, identify surviving shares and compare them with the threshold. Then identify who can approve a custody change. A redistribution proposal should assess availability and confidentiality together; lowering the threshold because rehearsal failed is insufficient. Prepare a committee message with the requirement, observation, gap, and options. At RUN handover, provide the dependency map, authorized-access procedure, and applicable rehearsal evidence. Existing material, reconstruction capability, and recovery authority are distinct conditions and should be reported as such.
Synthetic custody fixture; no real keys or secret-sharing implementation
threshold = 3
site A: share1, share2, share3
site B: share4, share5
Loss of A -> 2 distinct shares survive -> threshold not met
Two copies of share4 still count as ONE distinct share.A fictional archive’s custody rehearsal fails because primary-site loss removes three of five shares. The PM takes the distribution and alternatives to the competent authority.
Common pitfalls
Confusing rotation with re-encryption, counting accounts as people, averaging serial dependencies, and treating valid signatures as complete evidence after key exposure.
Related topics: Architecture, cryptography, and common failures · Networks, channels, and access boundaries · Secure software and supply chain
Cryptographic control depends on lifecycle, authority, and considered failures as well as the chosen algorithm.
Reference: Recommendation for Key Management: Part 1 General · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29