Cryptography Policy

Fill in the details

The preview updates as you type.

Cryptography Policy

Cryptography Policy

Company Name: 
Effective Date: 
Policy Owner: 
Approved By: 
Chief Information Security Officer: 

PURPOSE & SCOPE
- This policy defines the Organization's requirements for the use of cryptographic controls to protect the confidentiality, integrity, and authenticity of information assets. It establishes standards for encryption algorithms, key management, and certificate management.
- This policy applies to all cryptographic controls implemented on Organization systems, networks, applications, and data stores, as well as all personnel responsible for the implementation, management, or use of cryptographic mechanisms.
- The CISO shall be responsible for approving cryptographic standards, overseeing key management practices, and ensuring that the Organization's use of cryptography complies with applicable laws and export control regulations.

ENCRYPTION STANDARDS
- All data classified as Confidential or Restricted shall be encrypted at rest using AES-256 or equivalent NIST-approved symmetric encryption algorithms. Full-disk encryption shall be enabled on all Organization-managed endpoints and removable media.
- All data transmitted across networks shall be encrypted using TLS 1.2 or higher. Legacy protocols including SSL, TLS 1.0, and TLS 1.1 shall be disabled on all Organization systems and services.
- Asymmetric encryption operations shall use RSA with a minimum key length of 2048 bits or Elliptic Curve Cryptography with a minimum key length of 256 bits. Algorithms with known vulnerabilities, including DES, 3DES, RC4, and MD5, are prohibited.

KEY MANAGEMENT
- Cryptographic keys shall be generated using cryptographically secure random number generators and shall be managed throughout their lifecycle, including generation, distribution, storage, rotation, archival, and destruction.
- Encryption keys shall be rotated at intervals defined by their classification and use: at least annually for data encryption keys protecting Confidential data, and at least every two years for keys protecting Internal data. Certificate authority keys shall be rotated in accordance with the CA's certificate policy.
- Cryptographic keys shall be stored in hardware security modules or approved key management systems. Private keys shall never be stored in plain text, embedded in source code, or transmitted without encryption.

CERTIFICATE MANAGEMENT
- Digital certificates used for TLS, code signing, email encryption, and authentication shall be issued by the Organization's internal certificate authority or by a trusted external certificate authority approved by the CISO.
- A centralised certificate inventory shall be maintained that tracks all active certificates, their expiration dates, associated systems, and responsible owners. Automated monitoring shall alert administrators at least 60 days before certificate expiration.
- Compromised or no-longer-needed certificates shall be revoked immediately through the Organization's certificate revocation process. Certificate revocation lists and OCSP responders shall be maintained and available at all times.

COMPLIANCE & POLICY REVIEW
- The Information Security team shall conduct semi-annual audits of the Organization's cryptographic controls, including encryption coverage, algorithm compliance, key management practices, and certificate inventory accuracy.
- Violations of this policy, including the use of prohibited algorithms, improper key storage, or failure to encrypt data as required, shall result in disciplinary action and may require immediate remediation to prevent data exposure.
- This policy shall be reviewed at least annually by the CISO. Reviews shall assess the continued suitability of approved algorithms in light of advances in quantum computing, cryptanalysis, and changes to NIST and ISO 27001 guidance.
The complete guide

Everything you need to know

01What Is a Cryptography Policy?

A cryptography policy sets the rules for how a company uses encryption to protect data at rest and in transit. It specifies approved algorithms, key lengths, and protocols, and defines how encryption keys are generated, stored, rotated, and destroyed. The policy ensures that sensitive information stays unreadable to unauthorized parties and that the organization uses consistent, up to date cryptographic standards rather than ad hoc choices.

02Why Companies Need a Cryptography Policy

Encryption is only effective when it is applied correctly and keys are managed securely. A cryptography policy prevents weak or outdated algorithms from creeping in, standardizes protection across teams, and supports compliance with regulations that mandate encryption of personal or financial data. It also reduces the risk that a lost laptop or intercepted transmission turns into a reportable data breach.

03What a Cryptography Policy Should Include

List approved algorithms and minimum key lengths, and ban deprecated ones like outdated TLS versions. Require encryption for sensitive data at rest and in transit. Define a full key management lifecycle covering generation, storage, rotation, and revocation, along with who is authorized to handle keys. Include rules for removable media and a schedule to review standards as cryptography evolves.

Keep your hiring moving

Ready to interview your shortlist?

Send one link. Candidates record answers on their own time and AI ranks your shortlist, no scheduling, no back-and-forth.

Frequently asked questions