A.8.24A.8 Technological controls

Use of cryptography

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.8.24 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Define and apply rules for using cryptography effectively, including key management, to protect confidentiality, authenticity and integrity.

How to meet this control

In short: Define and implement rules for effective use of cryptography and key management.

  1. Step 01Publish a cryptography policy defining approved algorithms, minimum key lengths and where encryption is mandatory
  2. Step 02Enforce TLS 1.2 or above for data in transit and disable weak ciphers and outdated protocols on servers and load balancers
  3. Step 03Encrypt data at rest across databases, storage and backups using platform encryption with managed keys
  4. Step 04Manage keys through a dedicated key management service (Azure Key Vault, AWS KMS, HashiCorp Vault) covering generation, rotation, revocation and destruction
  5. Step 05Restrict and log access to keys, separating key administration from data access, and protect keys against loss and disclosure
  6. Step 06Account for legal restrictions on cryptography and cross-border key movement

Tip: A cryptography policy: TLS in transit, encryption at rest, defined key handling.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Establish a topic-specific cryptography policy setting general principles
  • ›Match the type, strength and quality of algorithms to the classification of the information
  • ›Use cryptography to protect data on mobile devices and storage media and in transit
  • ›Define a key management approach covering generation, protection and recovery
  • ›Assign clear roles and approve the standards, algorithms and cipher strengths allowed
  • ›Account for national legal restrictions on cryptography and cross-border movement
  • ›Run secure key management across the full lifecycle: generate, distribute, store, change, revoke, destroy
  • ›Protect all keys against modification, loss and disclosure, and log and audit key activity

Audit evidence to keep

  • - Cryptography policy listing approved algorithms and key lengths
  • - TLS configuration or scan showing strong ciphers and protocols
  • - Evidence of encryption at rest on databases, storage and backups
  • - Key management service configuration with rotation policy
  • - Key access and rotation audit logs

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.8.24. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all technological controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.