6.7.1 Cryptographic controls
The policy on the use of cryptographic controls must take account of jurisdictions that require cryptography for particular categories of personal data such as health data or national identifiers, the organization must t
4
artefacts
0
held by a system
0
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Cryptographic policy referencing jurisdiction specific mandates for categories of personal data · Policy repository / GRC workspace
- Documentation issued to customers describing where cryptography is applied and to what · Policy repository / GRC workspace
- Description of customer facing cryptographic capabilities such as customer managed keys · Policy repository / GRC workspace
- Key management procedures covering generation, storage, rotation, escrow and destruction · Policy repository / GRC workspace
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Jurisdictional cryptography mandates unmapped, so a category of data crosses into a jurisdiction that requires more than is applied
- Customer told that data is encrypted with no statement of what that covers, leaving a false impression
- Customer managed key capability offered without documenting the recovery consequences
- Key destruction never performed, so cryptographic erasure cannot be relied on
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet6.6.4 System and application access control · 6.8.1 Secure areas