Cryptographic Controls and Key Management Policy Template
Written By Micah
Many frameworks require a documented policy for the protection of confidential and sensitive data from the threat of misuse or disclosure. An encryption or cryptography policy outlines the technology used to protect data in transit, data at rest, key management, email encryption, and encryption of removable devices.
Commonly associated evidence:
Encryption Policy
Who needs a policy like this?
Businesses that need to conform to SOC 2, ISO 27001, ISO 27701, PCI, and GDPR.
How to use the template:
Click on the link above to access the template
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload
Questions?
Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.