You're exploring a read-only demo — nothing you click is saved. Back to site →
Sample workspace
Sign in
← Policies
ISO 27001

Cryptography Policy

Export DOCX / PDF

Cryptography Policy

Northwind Logistics GmbH · ISO/IEC 27001

Cryptography is used to protect the confidentiality, integrity and authenticity of information in line with its classification.

Requirements

  • Personal and confidential data is encrypted at rest and in transit.
  • Only approved algorithms and protocols (e.g. AES-256, TLS 1.2+) are used.
  • Cryptographic keys are generated, stored, rotated and revoked through a managed key-management process.
  • Legacy and deprecated algorithms are not permitted for new systems.

Exceptions require documented risk acceptance by the CISO.