ISO/IEC 27001:2022 Annex A · Control 8.24
Use of Cryptography: A Practical Implementation Guide
Use approved cryptography and manage keys so confidentiality, integrity and authenticity remain dependable.
This control concerns defining and implementing rules for effective use of cryptography and key management.
What should the control achieve?
- Cryptographic use cases and approved methods are defined.
- Keys have accountable lifecycle management.
- Legacy and prohibited algorithms are controlled.
- Legal and contractual constraints are considered.
Step-by-step implementation
Identify use cases
Cover data at rest, transit, authentication, signing, backups and secrets.
Set approved standards
Define algorithms, key sizes, protocols, certificate requirements and deprecation.
Design key lifecycle
Address generation, storage, distribution, rotation, backup, recovery, revocation and destruction.
Assign ownership
Separate key administration and define custodians and service owners.
Implement and inventory
Track certificates, keys, HSMs, libraries and dependencies.
Monitor and migrate
Alert on expiry, weak protocols, compromise and cryptographic change.
What this could look like in practice
A company mandates modern TLS, managed disk encryption and HSM-protected signing keys. Certificate inventory alerts 60 days before expiry, and compromised keys follow an emergency revocation playbook.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Data transit | Approved TLS configuration protects external service. | Scan result |
| Signing | HSM restricts key use and records operations. | HSM log |
| Certificate lifecycle | Automated renewal prevents expiry. | Certificate inventory |
| Compromise | Key is revoked and dependent systems are updated. | Incident record |
Implementation evidence
- Cryptography policy
- Approved-algorithm standard
- Key inventory
- Certificate inventory
- HSM or vault configuration
- Rotation logs
- Expiry monitoring
- Revocation tests
Useful metrics
- Certificates near expiry
- Weak protocols detected
- Keys past rotation
- Unmanaged cryptographic assets
Common mistakes
- Building custom cryptography.
- Storing keys with encrypted data.
- No recovery plan for critical keys.
- Ignoring certificate and library inventory.
- Encrypting data while exposing keys broadly.
Questions an auditor may ask
- Which cryptography is approved?
- How are keys generated and stored?
- Show rotation or revocation.
- How are algorithm changes managed?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.