# Cryptography and key management policy

Source: https://aestech.com.au/policy-templates/#cryptography-and-key-management-policy
Markdown URL: https://aestech.com.au/policy-templates/cryptography-and-key-management-policy.md

Use for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how encryption and cryptographic keys are selected, used, protected, rotated and retired.

2. Requirements
- Use TLS for data in transit where confidential or customer data is transmitted.
- Encrypt confidential and restricted data at rest where supported.
- Store secrets in approved secret managers, not source code or documents.
- Limit access to keys to authorised roles.
- Rotate keys after compromise, staff changes affecting key access, or according to system requirements.
- Retire and destroy keys when no longer needed.

3. Evidence
Keep encryption configuration, key access records, rotation logs, secret scanning results, exceptions and incident records.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md