Expert Advice Community

Guest

Applicability of A.10.1 Cryptographic Controls

  Quote
Guest
Guest user Created:   Jan 24, 2020 Last commented:   Jan 24, 2020

Applicability of A.10.1 Cryptographic Controls

Our organization uses Digital Certificates for Internet facing services, apart from that we do not use any cryptography. In this case, would A.10 be applicable to our organization?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Jan 24, 2020

If you are referring to SSL certificates, then control A.10.1.1 Policy on the use of cryptographic controls is probably applicable to you, while control A.10.1.2 Key management may not be applicable because you are not handling keys. 

But you primarily need to assess your risks, and analyze requirements to define which controls are applicable and which not. 

Here are a couple of helpful articles:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 24, 2020

Jan 24, 2020