Use of cryptography
Purpose
Define and apply rules for using cryptography effectively, including key management, to protect confidentiality, authenticity and integrity.
How to meet this control
In short: Define and implement rules for effective use of cryptography and key management.
- Step 01Publish a cryptography policy defining approved algorithms, minimum key lengths and where encryption is mandatory
- Step 02Enforce TLS 1.2 or above for data in transit and disable weak ciphers and outdated protocols on servers and load balancers
- Step 03Encrypt data at rest across databases, storage and backups using platform encryption with managed keys
- Step 04Manage keys through a dedicated key management service (Azure Key Vault, AWS KMS, HashiCorp Vault) covering generation, rotation, revocation and destruction
- Step 05Restrict and log access to keys, separating key administration from data access, and protect keys against loss and disclosure
- Step 06Account for legal restrictions on cryptography and cross-border key movement
Tip: A cryptography policy: TLS in transit, encryption at rest, defined key handling.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Establish a topic-specific cryptography policy setting general principles
- ›Match the type, strength and quality of algorithms to the classification of the information
- ›Use cryptography to protect data on mobile devices and storage media and in transit
- ›Define a key management approach covering generation, protection and recovery
- ›Assign clear roles and approve the standards, algorithms and cipher strengths allowed
- ›Account for national legal restrictions on cryptography and cross-border movement
- ›Run secure key management across the full lifecycle: generate, distribute, store, change, revoke, destroy
- ›Protect all keys against modification, loss and disclosure, and log and audit key activity
Audit evidence to keep
- - Cryptography policy listing approved algorithms and key lengths
- - TLS configuration or scan showing strong ciphers and protocols
- - Evidence of encryption at rest on databases, storage and backups
- - Key management service configuration with rotation policy
- - Key access and rotation audit logs
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.8.24. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.