CNSSP 15 establishes one suite of NSA-approved public algorithms for all NSS use of public cryptography, classified and unclassified alike. NSA may approve other algorithms for specific requirements, with guidance that restricts where the approval applies; NSA Encryption Production and Solutions must approve the use of any other cryptographic algorithm in NSS; the National Manager approves all NSS algorithm and protocol use and deviations; and NSA may update the approved list on a decision of the National Manager notified to the CNSS without reissuing the policy (paragraph 11 says Annex C, but the list is in Annex B). Using an algorithm the National Manager has not approved requires a waiver specific to the algorithm, the implementation and the use case; a commercial product that does not use CNSA 2.0 algorithms may not protect NSS without specific written NSA guidance; any use of Suite B or CNSA 1.0 algorithms must move to CNSA 2.0 on the CNSSP 15 timeframe. High-grade equipment follows CJCSN 6510 and CNSSAM 01-07-NSM instead.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.