Frameworks / ISO 27001:2022 / 8.24 ISO 27001:2022
Technological controls – ISO 27001:2022
ISO 27001:2022 8.24: Use of cryptography The organization is to define and apply rules for using cryptography effectively, key management included. Purpose (stated in ISO/IEC 27002:2022): makes cryptography work correctly to keep information confidential, genuine or unaltered as business, security and legal needs require. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.24.
Maintained by Gerard Blokdyk · Verified against the published standard 18 August 2026 · Control text last updated 25 September 2026 What else in your programme already covers this This control maps to 163 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 2.2.7 2.2.7 Non-console administrative access encrypted 2.3.2 2.3.2 Wireless encryption keys changed on triggers 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted 3.5.1 3.5.1 Stored PAN rendered unreadable 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations 3.7.2 3.7.2 Secure distribution of cryptographic keys 3.7.3 3.7.3 Secure storage of cryptographic keys 3.7.4 3.7.4 Key changes at end of cryptoperiod 3.7.5 3.7.5 Retirement, replacement or destruction of keys 3.7.6 3.7.6 Split knowledge and dual control for manual key operations 3.7.7 3.7.7 Prevent unauthorized substitution of keys 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 4.2.2 4.2.2 PAN secured when sent by end-user messaging 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 9.2.4 9.2.4 Locking of consoles in sensitive areas 3.3.1 3.3.1 SAD not retained after authorization, even encrypted 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse 3.7.1 3.7.1 Generation of strong cryptographic keys AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-18(1) Authentication and Encryption AC-19(5) Full Device or Container-Based Encryption CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-7 Cryptographic Module Authentication SC-12 Cryptographic Key Establishment and Management SC-13 Cryptographic Protection SC-17 Public Key Infrastructure Certificates SC-20 Secure Name/Address Resolution Service (Authoritative) SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection SC-8(1) Cryptographic Protection SI-7(1) Integrity Checks AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-18(1) Authentication and Encryption AC-19(5) Full Device or Container-Based Encryption CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-7 Cryptographic Module Authentication SC-12 Cryptographic Key Establishment and Management SC-13 Cryptographic Protection SC-17 Public Key Infrastructure Certificates SC-20 Secure Name/Address Resolution Service (Authoritative) SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection SC-8(1) Cryptographic Protection SI-7(1) Integrity Checks CIS-11.3 Protect Recovery Data CIS-12.3 Securely Manage Network Infrastructure CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-2.7 Allowlist Authorized Scripts CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.6 Encrypt Data on End-User Devices CIS-3.9 Encrypt Data on Removable Media CIS-4.6 Securely Manage Enterprise Assets and Software CIS-9.5 Implement DMARC ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required ASBv3-DP-6 Use a secure key management process ASBv3-DP-7 Use a secure certificate management process ASBv3-GS-3 Define and implement data protection strategy DP-3 Encrypt sensitive data in transit DP-4 Enable data at rest encryption by default 6.7 Cryptography 6.7.1 Cryptographic controls 7.3.10 Automated decision making 7.4.9 PII transmission controls 8.4.3 PII transmission controls 8.5.1 Basis for PII transfer between jurisdictions NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.PS-01 Configuration management practices are established and applied 03.05.04 Replay-Resistant Authentication 03.13.08 Transmission Confidentiality and Integrity 03.13.10 Cryptographic Key Establishment and Management 03.13.11 Cryptographic Protection 03.13.15 Session Authenticity ANSSI-HYG-11 Protect Passwords Stored on Systems ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet ANSSI-HYG-21 Use Secure Protocols Wherever They Exist ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost C5-CRY-01 Policy for the use of encryption procedures and key management C5-CRY-02 Encryption of data for transmission (transport encryption) C5-CRY-03 Encryption of sensitive data for storage C5-CRY-04 Secure key management SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal 8.21 Security of network services 8.24 Use of cryptography ASD37-17 TLS encryption between email servers (Limited) AUCDR-IS-2 Secure the network and systems within the data environment Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption 161R1-SC-8 Transmission Confidentiality and Integrity 3.14.1e Verify Integrity of Security Critical Software and Firmware Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technological controls – ISO 27001:2022 You are reading one control. How much of ISO 27001:2022 have you already done? ISO 27001:2022 8.24 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 163 it maps to, and the evidence behind each claim, over MCP and REST.