ISO 27001:2022
Technological controls – ISO 27001:2022

ISO 27001:2022 8.24: Use of cryptography

The organization is to define and apply rules for using cryptography effectively, key management included. Purpose (stated in ISO/IEC 27002:2022): makes cryptography work correctly to keep information confidential, genuine or unaltered as business, security and legal needs require. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.24.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 163 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 28 controls

  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 2.2.7 2.2.7 Non-console administrative access encrypted
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted
  • 3.5.1 3.5.1 Stored PAN rendered unreadable
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.2 3.7.2 Secure distribution of cryptographic keys
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 3.7.4 3.7.4 Key changes at end of cryptoperiod
  • 3.7.5 3.7.5 Retirement, replacement or destruction of keys
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks
  • 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography
  • 4.2.2 4.2.2 PAN secured when sent by end-user messaging
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 3.7.1 3.7.1 Generation of strong cryptographic keys

FedRAMP High · 14 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-18(1) Authentication and Encryption
  • AC-19(5) Full Device or Container-Based Encryption
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-7 Cryptographic Module Authentication
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-17 Public Key Infrastructure Certificates
  • SC-20 Secure Name/Address Resolution Service (Authoritative)
  • SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
  • SC-28 Protection of Information at Rest
  • SC-28(1) Cryptographic Protection
  • SC-8(1) Cryptographic Protection
  • SI-7(1) Integrity Checks

FedRAMP Moderate · 14 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-18(1) Authentication and Encryption
  • AC-19(5) Full Device or Container-Based Encryption
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-7 Cryptographic Module Authentication
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-17 Public Key Infrastructure Certificates
  • SC-20 Secure Name/Address Resolution Service (Authoritative)
  • SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
  • SC-28 Protection of Information at Rest
  • SC-28(1) Cryptographic Protection
  • SC-8(1) Cryptographic Protection
  • SI-7(1) Integrity Checks

CIS Controls v8 · 11 controls

  • CIS-11.3 Protect Recovery Data
  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-3.9 Encrypt Data on Removable Media
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-9.5 Implement DMARC

CMMC 2.0 · 9 controls

NIST SP 800-53 Rev 5 · 9 controls

  • ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required
  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-DP-7 Use a secure certificate management process
  • ASBv3-GS-3 Define and implement data protection strategy
  • DP-3 Encrypt sensitive data in transit
  • DP-4 Enable data at rest encryption by default

ISO 27701:2019 · 6 controls

  • 6.7 Cryptography
  • 6.7.1 Cryptographic controls
  • 7.3.10 Automated decision making
  • 7.4.9 PII transmission controls
  • 8.4.3 PII transmission controls
  • 8.5.1 Basis for PII transfer between jurisdictions
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied

NIST SP 800-171 Rev 3 · 5 controls

  • 03.05.04 Replay-Resistant Authentication
  • 03.13.08 Transmission Confidentiality and Integrity
  • 03.13.10 Cryptographic Key Establishment and Management
  • 03.13.11 Cryptographic Protection
  • 03.13.15 Session Authenticity
  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet
  • ANSSI-HYG-21 Use Secure Protocols Wherever They Exist
  • ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost

C5 (Germany) · 4 controls

  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-02 Encryption of data for transmission (transport encryption)
  • C5-CRY-03 Encryption of sensitive data for storage
  • C5-CRY-04 Secure key management

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

SOC 2 · 3 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal

ISO 27001:2013 · 2 controls

ISO 27002:2022 · 2 controls

  • 8.21 Security of network services
  • 8.24 Use of cryptography

APPI · 1 control

  • ASD37-17 TLS encryption between email servers (Limited)
  • AUCDR-IS-2 Secure the network and systems within the data environment

DORA · 1 control

GDPR · 1 control

NIS2 Directive · 1 control

  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • 161R1-SC-8 Transmission Confidentiality and Integrity

NIST SP 800-172 · 1 control

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 8.24 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 163 it maps to, and the evidence behind each claim, over MCP and REST.