ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.7.1: Cryptographic controls

The organization's cryptography policy must take account of jurisdictions that require cryptography for particular categories of personal data such as health data or national identifiers, the organization must tell the customer in what circumstances it applies cryptography to the personal data it processes, and must tell the customer about any capability it offers to help the customer apply cryptography of its own; key management applies as the base guidance requires.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 91 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 28 controls

  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 2.2.7 2.2.7 Non-console administrative access encrypted
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted
  • 3.5.1 3.5.1 Stored PAN rendered unreadable
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.2 3.7.2 Secure distribution of cryptographic keys
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 3.7.4 3.7.4 Key changes at end of cryptoperiod
  • 3.7.5 3.7.5 Retirement, replacement or destruction of keys
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography
  • 4.2.2 4.2.2 PAN secured when sent by end-user messaging
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 3.7.1 3.7.1 Generation of strong cryptographic keys

CMMC 2.0 · 8 controls

NIST SP 800-53 Rev 5 · 8 controls

CIS Controls v8 · 7 controls

  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-3.9 Encrypt Data on Removable Media

HIPAA Security Rule · 5 controls

NIST SP 800-66 Rev 2 · 5 controls

SOC 2 · 4 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required
  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-DP-7 Use a secure certificate management process
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected

C5 (Germany) · 2 controls

  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-04 Secure key management

FedRAMP High · 2 controls

  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection

FedRAMP Moderate · 2 controls

  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection

NIST SP 800-161 Rev 1 · 2 controls

  • AUCDR-IS-2 Secure the network and systems within the data environment
  • IS.I.OR.110 Cryptographic Controls

GDPR · 1 control

ISO 27001:2022 · 1 control

  • 8.24 Use of cryptography

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

ISO 27017:2015 · 1 control

  • 10.1 Cryptographic controls

ISO 27018:2019 · 1 control

  • 10.1 Cryptographic controls
  • 03.13.10 Cryptographic Key Establishment and Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.7.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.