Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.24

Use of Cryptography: A Practical Implementation Guide

Use approved cryptography and manage keys so confidentiality, integrity and authenticity remain dependable.

This control concerns defining and implementing rules for effective use of cryptography and key management.

Practical interpretation: Encryption strength depends on algorithms, protocols, implementation and key lifecycle. ‘Encrypted’ is not a complete security requirement.

What should the control achieve?

  • Cryptographic use cases and approved methods are defined.
  • Keys have accountable lifecycle management.
  • Legacy and prohibited algorithms are controlled.
  • Legal and contractual constraints are considered.

Step-by-step implementation

1

Identify use cases

Cover data at rest, transit, authentication, signing, backups and secrets.

2

Set approved standards

Define algorithms, key sizes, protocols, certificate requirements and deprecation.

3

Design key lifecycle

Address generation, storage, distribution, rotation, backup, recovery, revocation and destruction.

4

Assign ownership

Separate key administration and define custodians and service owners.

5

Implement and inventory

Track certificates, keys, HSMs, libraries and dependencies.

6

Monitor and migrate

Alert on expiry, weak protocols, compromise and cryptographic change.

What this could look like in practice

A company mandates modern TLS, managed disk encryption and HSM-protected signing keys. Certificate inventory alerts 60 days before expiry, and compromised keys follow an emergency revocation playbook.

ActivityPractical implementationEvidence
Data transitApproved TLS configuration protects external service.Scan result
SigningHSM restricts key use and records operations.HSM log
Certificate lifecycleAutomated renewal prevents expiry.Certificate inventory
CompromiseKey is revoked and dependent systems are updated.Incident record

Implementation evidence

  • Cryptography policy
  • Approved-algorithm standard
  • Key inventory
  • Certificate inventory
  • HSM or vault configuration
  • Rotation logs
  • Expiry monitoring
  • Revocation tests

Useful metrics

  • Certificates near expiry
  • Weak protocols detected
  • Keys past rotation
  • Unmanaged cryptographic assets

Common mistakes

  • Building custom cryptography.
  • Storing keys with encrypted data.
  • No recovery plan for critical keys.
  • Ignoring certificate and library inventory.
  • Encrypting data while exposing keys broadly.

Questions an auditor may ask

  • Which cryptography is approved?
  • How are keys generated and stored?
  • Show rotation or revocation.
  • How are algorithm changes managed?
Implementation test: Select a critical encrypted service and trace algorithm choice, key ownership, storage, rotation, recovery, expiry and compromise response.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.