ISO 27001 – Annex A.10: Cryptography

We make achieving ISO 27001 easy. Achieve Annex A.10 compliance

Achieve certification

What is the objective of Annex A.10.1 of ISO 27001:2013?

Annex A.10.1 is about Cryptographic controls. The objective in this Annex A control is to ensure proper and effective use of cryptography to protect the confidentiality, authenticity and/or integrity of information.

It’s an important part of the information security management system (ISMS) especially if you’d like to achieve ISO 27001 certification. Lets understand those requirements and what they mean in a bit more depth now.

A.10.1.1 Policy on the use of Cryptographic Controls

Encryption and cryptographic controls are often seen as one of the key weapons in the security arsenal, however, on its own it is not the “silver bullet” that solves every problem. Incorrect selection of cryptographic technologies and techniques or the poor management of cryptographic material (e.g. keys and certificates) can create vulnerabilities themselves.

Encryption can slow processing and transmission of information down so it is important to understand all of the risks and balance out the controls to an adequate level whilst also still meeting performance goals.

A policy on the use of encryption can be a good place to identify the business requirements for when encryption must be used and the standards that are to be implemented. Consideration must also be given to the legal requirements around encryption.

A.10.1.2 Key Management

A good control describes how a policy on the use and protection of Cryptographic Keys should be developed and implemented through their whole lifecycle. One of the most important aspects is around the creation, distribution, changes, back up and storage of cryptographic key material through to its end of life and destruction.

Management of key material is often the weakest point for encryption and attackers may seek to attack this rather than the encryption itself. It is therefore important to have robust and secure processes around it.  Dealing with compromised keys is also important and where appropriate should be tied into Annex A.16 Security Incident Management too.

Applying Encryption offers some guidance and tips towards a good policy for encryption however this is one of the few areas where it is unique to your business and the operational activities where you’d use encryption.

We do have a list of partners who provide specialist advice and products around encryption so if this is an area you need help with during your implementation let us know and we can put you in touch with trusted experts too.

Achieve your first ISO 27001

Download your free guide to fast and sustainable certification

We’re so pleased we found this solution, it made everything fit together more easily.
Emmie Cooney
Operations Manager Amigo
100% of our users pass certification first time
Book your demo

How to easily demonstrate A.10 Cryptography

The platform makes it easy for you to ensure proper and effective use of cryptography to protect the confidentiality, authenticity and/or integrity of information.

Adopt, adapt and add

Our pre-configured ISMS will enable you to evidence controls A.10.1.1-A.10.1.2 within our platform and easily adapt it to your organisation’s needs.

You are provided with ready-made controls and references to subordinate policies that can be adopted, adapted, or added to out of the box.

This means that you have ready-made simple to follow foundation for ISO 27001 compliance or certification giving you a 77% head start.

Adopt, adapt and add

ISO 27001 requirements

ISO 27001 Annex A Controls

About ISO 27001

The proven path to ISO 27001 success

Built with everything you need to succeed with ease, and ready to use straight out of the box – no training required!

Perfect Policies & Controls

Easily collaborate, create and show you are on top of your documentation at all times

Find out more

Simple Risk Management

Effortlessly address threats & opportunities and dynamically report on performance

Find out more

Measurement & Automated Reporting

Make better decisions and show you are in control with dashboards, KPIs and related reporting

Find out more

Audits, Actions & Reviews

Make light work of corrective actions, improvements, audits and management reviews

Find out more

Mapping & Linking Work

Shine a light on critical relationships and elegantly link areas such as assets, risks, controls and suppliers

Find out more

Easy Asset Management

Select assets from the Asset Bank and create your Asset Inventory with ease

Find out more

Fast, Seamless Integration

Out of the box integrations with your other key business systems to simplify your compliance

Find out more

Other Standards & Regulations

Neatly add in other areas of compliance affecting your organisation to achieve even more

Find out more

Staff Compliance Assurance

Engage staff, suppliers and others with dynamic end-to-end compliance at all times

Find out more

Supply Chain Management

Manage due diligence, contracts, contacts and relationships over their lifecycle

Find out more

Interested Party Management

Visually map and manage interested parties to ensure their needs are clearly addressed

Find out more

Strong Privacy & Security

Strong privacy by design and security controls to match your needs & expectations

Find out more

Take 30 minutes to see how saves you hours (and hours!)

Book a meeting