Encryption & Crypto Controls
Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal
1. Purpose
This policy protects the confidentiality and integrity of {{DATA_TYPES}} at {{COMPANY_LEGAL_NAME}} through strong, well-managed cryptography across the services we run in {{CRITICAL_SYSTEMS}} and the jurisdictions in {{GEO_SCOPE}}.
2. Scope
This policy applies to every system, application, database, backup, and communication channel that handles sensitive or confidential {{DATA_TYPES}}. It covers the {{LOCATION}} workforce, and only managed {{DEVICE_TYPES}} may access keys or configure cryptography on production systems in {{CRITICAL_SYSTEMS}}.
3. Policy statements
3.1 Encryption in transit
We require modern TLS for web, API, mail-relay, and administrative traffic to and from {{CRITICAL_SYSTEMS}}, disable weak ciphers and protocols, and enable strict transport security where it is supported. Service-to-service traffic carrying restricted {{DATA_TYPES}} uses mutual TLS or an equivalent, and we avoid split tunneling when sensitive data crosses {{GEO_SCOPE}}.
3.2 Encryption at rest
Provider-level encryption is enabled for cloud storage, volumes, and managed databases in {{CRITICAL_SYSTEMS}}, and full-disk encryption is required on {{DEVICE_TYPES}}, including removable drives. Backups and snapshots inherit the same key policies, and we record storage residency in {{GEO_SCOPE}} where it applies.
3.3 Key generation and storage
Keys are generated with approved cryptographic libraries or a cloud key management service in {{CRITICAL_SYSTEMS}} and stored in a managed vault or key management service, never hard-coded in source control. Vault access is limited to least-privilege service roles with detailed auditing, and logs are kept as {{GEO_SCOPE}} requires.
3.4 Key rotation and retirement
We rotate platform and database master keys at least annually and whenever we suspect compromise. Retired keys are revoked and destroyed, rotation events and affected assets are recorded, and we confirm old keys can no longer decrypt new data. Dependent secrets and configurations are updated as part of the same change.
3.5 Measurement and continual improvement
A monthly scan verifies encryption in transit and at rest, and a vault audit confirms there are no orphaned keys. For teams over {{EMPLOYEE_COUNT}} people we widen sampling across services in {{CRITICAL_SYSTEMS}}. We review our algorithms and configurations each year and upgrade whenever industry guidance deprecates a current standard, reflecting {{INDUSTRY}} and {{GEO_SCOPE}} change where relevant.
4. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Executive sponsor | Accountable for the program; approves this policy |
| {{POLICY_OWNER_ROLE}} | Maintains this policy and its procedures |
| Managers | Enforce the policy within their teams |
| All personnel | Comply; report issues promptly |
5. Compliance and exceptions
Plaintext storage or transmission of sensitive {{DATA_TYPES}} triggers immediate incident response and remediation. Any legacy system that cannot support encryption must be isolated and tracked under a mitigation plan, with documented risk acceptance by {{APPROVER_TITLE}} and any {{GEO_SCOPE}} residency constraint noted.
6. Review
This policy is reviewed at least annually and when significant change occurs.
Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.