ISO27001:2022 – A8.24

Use of cryptography

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.24

The purpose of this ISO27001 control is to ensure that cryptographic controls are in place, which ensure the confidentiality, authenticity or integrity of information. This is, of course, quite a technical area, but there are also compliance issues that need to be considered because the control is also concerned with the proper use of cryptographic techniques.

 This means you need to understand the business needs, alongside taking into consideration legal, statutory, regulatory and contractual requirements related to cryptography. 

What does the standard require?

The standard states that “Rules for the effective use of cryptography, including cryptographic key management shall be defined and implemented.” (A8.24 – Use of Cryptography) 

Note here that there are two aspects of this control, with the first concerned with the effective use of cryptography, and the second with key management.  Many will recognise these two requirements, as the new version of ISO27001 combined two separate controls into one, more succinct requirement. 

Why is this required?

The story of cryptography is a long and fascinating one. Keeping secrets from your adversaries goes all the way back to the dawn of civilisation. For example, a very simple cypher takes its name from the roman emperor who created and popularised it; The Caesar Cypher. 

In more modern times, the Enigma Machine and the Code breakers of Bletchley Park are worth researching, if you want to understand the importance of cryptography. 

In simple terms, without cryptographic controls in place, the information you access is not fully protected, and if it falsl into the wrong hands could be considered to be a data breach.

 For example, if end-to-end encryption is not in place, attackers can carry out ‘Man in the Middle’ (MiiM) attacks. A significant data breach could occur if the data is not encrypted if a device is lost or stolen.

 Encryption is an effective approach to ensure compliance with legal requirements, such as the General Data Protection Regulation (GDPR). Anonymising the data almost negates the need to report a data breach because encryption effectively makes the data unreadable (ie. it cannot be accessed) and therefore poses no threat or risk to the data subject.

After a break-in at their home, our client informed us that their laptop had been stolen along with the external hard drive they used to backup their data. The external hard drive had been left on the desk overnight and was attached to the device when it was stolen. 

Fortunately, the hard drive was encrypted and required 2FA to access the information. So although the theft was (understandably) distressing and disruptive, it meant that the client could rest assured that the data was secured and was not considered a reportable data breach.

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;

The auditor will be looking for the following to be in place;

What do you need to do?

 First of all it’s important to recognise that encryption is used in a number of places, but fundamentally you can think of it in two ways;

  • Encryption at rest – E.g. Data is stored on your laptop, server, USB drive
  • Encryption in transit – E.g. Data is being transmitted over the internet

Cryptography plays a vital role in protecting business critical and sensitive information. However, for it to be truly effective it needs to be implemented appropriately and thoughtfully.

Speak to your IT function to understand where encryption has been implemented. Ask for an outline of the network and talk about encryption in transit.  How do users connect to the internet? What devices are they using? Do they have a VPN in place?

Once you have an understanding of how data is transmitted, you can ask about what kind of encryption is used.  Then turn your attention to the devices that store data and ask how the data on those devices are secured. What form of encryption is in place?

Armed with this information you can identify any risks associated to the use of encryption and can develop appropriate policies (aka ‘Rules’) and procedures. For example your when a new device is deployed into your business, you can ensure that the latest form of encryption is enabled by default, and state what kind of encryption is permitted.

This last point is important, as the kind of encryption may be of relevance depending on where you are in the world. Some countries do not allow certain forms of encryption. This is something you will identify from your investigations surrounding legal, statutory and regulatory controls.

Make a list of all the places that use encryption and identify how they are managed.  Remembering that this control also includes a requirement to manage the creation and management of cryptographic keys, you need to know how this is controlled. 

It’s important to be aware that cryptographic controls can be broken, and not all forms of encryption are equal.  For example, if you have a website, you may have noticed that the URL has the prefix of ‘HTTPS’, meaning the site is secured using some form of encryption.  Historically, SSL (Secure Socket Layer) protocols were used and some still do., However, due to a number of security vulnerabilities identified in SSL, it is accepted that SSL be replaced by TLS (Transport Layer Security). At the time of writing, we are at TLS version 1.3.

Before finishing, we would say that no one is expecting you to become a cryptographic expert. But this control does ask you to understand how cryptography is used, and ensure it meets your business needs, while keeping in mind the requirements of legal and regulatory requirements.  Tools like VPNs, and MFA It’s your job to establish how these are managed and ensure they are appropriate, and that you balance security with useability.

Difficulty rating

We rate this a 2.5 out of 5 difficulty rating. This might be a control that you have little influence over as many applications and devices will be pre-loaded with some form of cryptographic controls, But it is more than a technical topic, as it requires an appreciation of business needs, and legal and regulatory understanding on how cryptography works.

Q&A

Do I need a policy?

Yes you should establish a policy (aka Rules) for the use of encryption, and outline when and how it should be utilised.  As with all policies, don’t be too specific in explaining what form of encryption you use, as these may change and you may have to update policies when one form of encryption is changed in favour of another.

Who should be responsible for key management?

This depends on the type of encryption you’re using, but key management is important. In more recent times, key management has become easier, but should still be owned by someone in your business.  We would suggest that you speak to the owner of the system or application in use and ask them how they generate new keys or revoke keys. For example, the person responsible for developing your website will normally also control your TLS (or SSL) certificate.  Ask them when the certificate will expire, and how it is managed.

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.24 –  Use of cryptography