Expert TipControls & Evidence

Cryptography Controls: What's Practical for Most Organisations

Demystifying cryptography requirements in ISO 27001 — what you actually need to implement and what auditors look for.

Updated 5 Mar 2026

Don't Panic

You don't need to be a cryptography expert. ISO 27001 requires a policy on cryptographic controls and proper key management — not that you build your own encryption algorithms.

What to Implement

Encryption at Rest

Full disk encryption on all laptops and workstations (BitLocker, FileVault)
Database encryption for sensitive data
Encrypted backups
Cloud storage encryption (most providers enable this by default)

Encryption in Transit

TLS 1.2+ for all web traffic (HTTPS everywhere)
TLS for email where possible
VPN for remote access
SFTP/SCP instead of FTP for file transfers

Key Management

Document who has access to encryption keys
Define key rotation schedule
Secure key storage (HSM, key vault, or equivalent)
Recovery procedures for lost keys
Separation of duties for key management

The Policy

Your cryptography policy should cover:

1. When encryption is required (data classification drives this)

2. Approved algorithms and minimum key lengths

3. Key management responsibilities

4. Key lifecycle: generation, storage, rotation, revocation, destruction

5. Compliance with legal requirements (e.g., export controls)

What Auditors Check

Is there a documented cryptography policy?
Are laptops encrypted? (They'll ask to see a sample)
Is web traffic using current TLS versions?
How are keys managed and who has access?
Are there any legacy systems using weak encryption?

Common Mistakes

Relying on default encryption without understanding what it covers
No key management process (keys stored in source code or shared documents)
Using deprecated protocols (TLS 1.0, SSL, SHA-1)
Encrypting data but losing the ability to decrypt (key management failure)
Not including cryptography in the risk assessment

Related Modules

Standard Controls
Documents

Related Controls / Clauses

A.8.24

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.