***CON_CRYPTO-1** To prevent rollback or downgrade [i.17] the product shall:
***CON_CRYPTO-1** To prevent rollback or downgrade the product shall:
1. enforce a monotonic cipher suite policy configuration (or equivalent mechanism);
2. preven the re-enabling of deprecated algorithms or the disabling of security checks via a rollback operation without having an explicit logged administrative override in place.
> NOTE: More details for **CON_CRYPTO-1** in ETSI EN 304 642 [i.17]
### 5.7.2 Secure channel
***CON_CHANNEL-1** The product shall ensure that the secure channel uses cryptographic functions and configuration according to the Annex K.