Free policy template ISO 27001

Encryption & Cryptographic Controls Policy

Where encryption is required (in transit and at rest), acceptable algorithms, and how keys are managed.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Encryption & Crypto Controls

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

This policy protects the confidentiality and integrity of {{DATA_TYPES}} at {{COMPANY_LEGAL_NAME}} through strong, well-managed cryptography across the services we run in {{CRITICAL_SYSTEMS}} and the jurisdictions in {{GEO_SCOPE}}.

2. Scope

This policy applies to every system, application, database, backup, and communication channel that handles sensitive or confidential {{DATA_TYPES}}. It covers the {{LOCATION}} workforce, and only managed {{DEVICE_TYPES}} may access keys or configure cryptography on production systems in {{CRITICAL_SYSTEMS}}.

3. Policy statements

3.1 Encryption in transit

We require modern TLS for web, API, mail-relay, and administrative traffic to and from {{CRITICAL_SYSTEMS}}, disable weak ciphers and protocols, and enable strict transport security where it is supported. Service-to-service traffic carrying restricted {{DATA_TYPES}} uses mutual TLS or an equivalent, and we avoid split tunneling when sensitive data crosses {{GEO_SCOPE}}.

3.2 Encryption at rest

Provider-level encryption is enabled for cloud storage, volumes, and managed databases in {{CRITICAL_SYSTEMS}}, and full-disk encryption is required on {{DEVICE_TYPES}}, including removable drives. Backups and snapshots inherit the same key policies, and we record storage residency in {{GEO_SCOPE}} where it applies.

3.3 Key generation and storage

Keys are generated with approved cryptographic libraries or a cloud key management service in {{CRITICAL_SYSTEMS}} and stored in a managed vault or key management service, never hard-coded in source control. Vault access is limited to least-privilege service roles with detailed auditing, and logs are kept as {{GEO_SCOPE}} requires.

3.4 Key rotation and retirement

We rotate platform and database master keys at least annually and whenever we suspect compromise. Retired keys are revoked and destroyed, rotation events and affected assets are recorded, and we confirm old keys can no longer decrypt new data. Dependent secrets and configurations are updated as part of the same change.

3.5 Measurement and continual improvement

A monthly scan verifies encryption in transit and at rest, and a vault audit confirms there are no orphaned keys. For teams over {{EMPLOYEE_COUNT}} people we widen sampling across services in {{CRITICAL_SYSTEMS}}. We review our algorithms and configurations each year and upgrade whenever industry guidance deprecates a current standard, reflecting {{INDUSTRY}} and {{GEO_SCOPE}} change where relevant.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
{{POLICY_OWNER_ROLE}} Maintains this policy and its procedures
Managers Enforce the policy within their teams
All personnel Comply; report issues promptly

5. Compliance and exceptions

Plaintext storage or transmission of sensitive {{DATA_TYPES}} triggers immediate incident response and remediation. Any legacy system that cannot support encryption must be isolated and tracked under a mitigation plan, with documented risk acceptance by {{APPROVER_TITLE}} and any {{GEO_SCOPE}} residency constraint noted.

6. Review

This policy is reviewed at least annually and when significant change occurs.


Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates