5.21 Encryption - 'Use a procedure that employs a content data element as the encryption key that is unique for each record.'

Information

By employing a procedure that uses data elements that change for each record the resulting ciphertext will be unique. As an example
if the same value, key, and encryption are used for a value in a record the resulting ciphertext will be identical. Someone knowing
the value of one of the records independent of the ciphertext can by inference know the value of other records that display the same ciphertext.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.as manual verification is required in order to determine which elements require an encryption key.

Solution

Where possible, use a procedure that employs a content data element as the encryption key that is unique for each record

See Also

https://workbench.cisecurity.org/files/574