Cryptography Controls: What's Practical for Most Organisations
Demystifying cryptography requirements in ISO 27001 — what you actually need to implement and what auditors look for.
Updated 5 Mar 2026
Don't Panic
You don't need to be a cryptography expert. ISO 27001 requires a policy on cryptographic controls and proper key management — not that you build your own encryption algorithms.
What to Implement
Encryption at Rest
•Full disk encryption on all laptops and workstations (BitLocker, FileVault)
•Database encryption for sensitive data
•Encrypted backups
•Cloud storage encryption (most providers enable this by default)
Encryption in Transit
•TLS 1.2+ for all web traffic (HTTPS everywhere)
•TLS for email where possible
•VPN for remote access
•SFTP/SCP instead of FTP for file transfers
Key Management
•Document who has access to encryption keys
•Define key rotation schedule
•Secure key storage (HSM, key vault, or equivalent)
•Recovery procedures for lost keys
•Separation of duties for key management
The Policy
Your cryptography policy should cover:
1. When encryption is required (data classification drives this)
5. Compliance with legal requirements (e.g., export controls)
What Auditors Check
•Is there a documented cryptography policy?
•Are laptops encrypted? (They'll ask to see a sample)
•Is web traffic using current TLS versions?
•How are keys managed and who has access?
•Are there any legacy systems using weak encryption?
Common Mistakes
•Relying on default encryption without understanding what it covers
•No key management process (keys stored in source code or shared documents)
•Using deprecated protocols (TLS 1.0, SSL, SHA-1)
•Encrypting data but losing the ability to decrypt (key management failure)
•Not including cryptography in the risk assessment
Related Modules
Standard Controls
Documents
Related Controls / Clauses
A.8.24
26 practitioner guides — included free with your workspace
27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.