A.8.24
    Technological Controls

    Use of cryptography

    Rules for the effective use of cryptography, including cryptographic key management, should be defined and implemented.

    Purpose

    To ensure proper and effective use of cryptography to protect confidentiality, authenticity and integrity of information.

    Implementation Guidance

    Define cryptography policy and standards

    Use strong, approved cryptographic algorithms

    Implement encryption for data at rest and in transit

    Establish key management procedures

    Use TLS for network communications

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.24 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.24 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.24 Use of cryptography. Built for compliance professionals.

    Try ISMS Copilot free