ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.24: Use of cryptography

The organization is to define and apply rules for using cryptography effectively, key management included. Purpose: apply cryptography correctly and to good effect so information stays confidential, genuine or unaltered in line with business and security requirements and the legal, regulatory and contractual rules on cryptography. Guidance: consider a topic-specific cryptography policy setting general principles, needed to gain the benefits and avoid misuse; the protection level and classification of information, which determine the type, strength and quality of algorithms; encryption of information on mobile endpoints and storage media and in transit to them; the approach to key management, including generating and protecting keys and recovering encrypted information when keys are lost, compromised or damaged; roles for implementing the rules and for key management including generation; approved or mandatory standards, algorithms, cipher strengths, solutions and usage practices; and the effect of encryption on controls that inspect content, such as malware detection or content filtering. Take into account national regulations and restrictions on cryptography in different countries and cross-border flows of encrypted information (5.31), and make agreements with external cryptographic service providers such as certification authorities cover liability, service reliability and response times (5.22). Keys need secure handling across their whole life, from creation, storage, archiving, retrieval and distribution to retirement and destruction, based on agreed standards and procedures for: generating keys for different systems and applications; issuing and obtaining public key certificates; distributing keys to intended parties and activating them on receipt; storing keys and granting authorized access; changing or updating keys, with rules on when and how; handling compromised keys; revoking or deactivating keys, for instance on compromise or when a user leaves, archiving them in that case; recovering lost or corrupted keys; making backup or archive copies of keys; destruction of keys; logging and auditing key management; setting activation and deactivation dates so keys are used only within their permitted period; and handling legal demands for access to keys, such as producing decrypted evidence in court. All keys need protection from modification and loss, and secret and private keys also from unauthorized use and disclosure; equipment that generates, stores or archives keys is physically protected, and the authenticity of public keys often matters too. Other information: public key authenticity is usually handled through certificate authorities and certificates, or manually for small numbers of keys; cryptography supports confidentiality (encryption), integrity and authenticity (digital signatures, message authentication codes, file integrity checks), non-repudiation and authentication of users and entities; ISO/IEC 11770 covers key management.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 187 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 28 controls

  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 2.2.7 2.2.7 Non-console administrative access encrypted
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted
  • 3.5.1 3.5.1 Stored PAN rendered unreadable
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.2 3.7.2 Secure distribution of cryptographic keys
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 3.7.4 3.7.4 Key changes at end of cryptoperiod
  • 3.7.5 3.7.5 Retirement, replacement or destruction of keys
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 4.2.2 4.2.2 PAN secured when sent by end-user messaging
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 3.7.1 3.7.1 Generation of strong cryptographic keys
  • 6.4.3 6.4.3 Payment page script management
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts

FedRAMP High · 13 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-19(5) Full Device or Container-Based Encryption
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-5(2) Public Key-Based Authentication
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-17 Public Key Infrastructure Certificates
  • SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
  • SC-28 Protection of Information at Rest
  • SC-28(1) Cryptographic Protection
  • SC-8 Transmission Confidentiality and Integrity
  • SC-8(1) Cryptographic Protection
  • SI-7 Software, Firmware, and Information Integrity

FedRAMP Moderate · 13 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-19(5) Full Device or Container-Based Encryption
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-5(2) Public Key-Based Authentication
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-17 Public Key Infrastructure Certificates
  • SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
  • SC-28 Protection of Information at Rest
  • SC-28(1) Cryptographic Protection
  • SC-8 Transmission Confidentiality and Integrity
  • SC-8(1) Cryptographic Protection
  • SI-7 Software, Firmware, and Information Integrity
  • ISM-0455 Data recovery for encrypted data
  • ISM-0457 Evaluated encryption for sensitive media
  • ISM-0462 Handling authenticated encrypted equipment and media
  • ISM-0471 Using ASD-Approved Cryptographic Algorithms
  • ISM-0481 Using ASD-Approved Cryptographic Protocols
  • ISM-0507 Cryptographic key management processes
  • ISM-1091 Changing compromised keying material
  • ISM-1956 Changing AD FS certificates
  • ISM-2050 Validating digital signatures and revocation

NIST SP 800-53 Rev 5 · 9 controls

  • ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required
  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-DP-7 Use a secure certificate management process
  • BR-2 Protect backup and recovery data
  • DP-3 Encrypt sensitive data in transit
  • DP-4 Enable data at rest encryption by default
  • IM-4 Authenticate server and services
  • EIDAS-Art.26 Requirements for advanced electronic signatures
  • EIDAS-Art.28 Qualified certificates for electronic signatures
  • EIDAS-Art.29 Qualified electronic signature creation devices (QSCDs)
  • EIDAS-Art.32 Validation of qualified electronic signatures
  • EIDAS-Art.38 Qualified certificates for electronic seals
  • EIDAS-Art.40 Validation and preservation of qualified electronic seals
  • EIDAS-Art.45 Requirements for qualified certificates for website authentication

C5 (Germany) · 6 controls

  • C5-COS-08 Policies for data transmission
  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-02 Encryption of data for transmission (transport encryption)
  • C5-CRY-03 Encryption of sensitive data for storage
  • C5-CRY-04 Secure key management
  • C5-OPS-09 Data Backup and Recovery - Storage

CIS Controls v8 · 6 controls

  • CIS-11.3 Protect Recovery Data
  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-3.9 Encrypt Data on Removable Media

CMMC 2.0 · 6 controls

ETSI EN 303 645 · 6 controls

  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet
  • ANSSI-HYG-21 Use Secure Protocols Wherever They Exist
  • ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost

HIPAA Security Rule · 4 controls

  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected

NIST SP 800-66 Rev 2 · 4 controls

SOC 2 · 4 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-P4.3 P4.3 Securely disposing of personal information

ISO 27701:2019 · 3 controls

  • 6.7 Cryptography
  • 6.7.1 Cryptographic controls
  • 7.4.9 PII transmission controls

MTCS (Singapore) · 3 controls

  • 17.2 Encryption policies and procedures
  • 17.3 Channel encryption
  • 17.4 Key management
  • SEC.EAR Encryption at rest of in-scope data, or the four compensating controls
  • SEC.KEY Encryption key management policy covering the key lifecycle

IEC 62443 · 2 controls

  • 62443-3-3-FR3-SR-3-1 Communication Integrity (FR3 System Integrity)
  • 62443-3-3-FR4-SR-4-1 Information Confidentiality (FR4 Data Confidentiality)

NIST SP 800-171 Rev 3 · 2 controls

  • 03.13.10 Cryptographic Key Establishment and Management
  • 03.13.11 Cryptographic Protection
  • POLICY Set and review the cryptographic policy
  • PRIMITIVES Choose the recommended post-quantum and symmetric primitives and parameters
  • P2-5.3.3 P2-5.3.3 No rollback to unapproved algorithms or key sizes
  • P2-6.1.6 P2-6.1.6 Key management follows recognised standards
  • ASD37-17 TLS encryption between email servers (Limited)
  • AUCDR-IS-2 Secure the network and systems within the data environment

DORA · 1 control

GDPR · 1 control

ISO 27001:2022 · 1 control

  • 8.24 Use of cryptography

ISO/IEC 27011:2024 · 1 control

  • 27011-8.24 Use of Cryptography

ISO/IEC 42001:2023 · 1 control

  • A.9 Use of AI systems

NIS2 Directive · 1 control

  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • 161R1-SC-8 Transmission Confidentiality and Integrity

NIST SP 800-172 · 1 control

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware

NIST SP 800-218 · 1 control

NY DFS 23 NYCRR 500 · 1 control

  • §500.15 Encryption of Nonpublic Information
  • 17.9.33.C.02 17.9.33.C.02 Triggers and frequency for cryptographic audits

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.24 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 187 it maps to, and the evidence behind each claim, over MCP and REST.