Expert Advice Community

Guest

Use of cryptographic controls

  Quote
Guest
Guest user Created:   Mar 31, 2018 Last commented:   Mar 31, 2018

Use of cryptographic controls

Can you please elaborate what kind of controls addressing under 10.1.1, as we as an organization just implemented the SSL certificate for securing our web interfaces acessed by external or remote users, in this regard can 10.1.1 caluse will be applicabe or not, in case it applicate so what kind the policy we have to draft at our side.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 31, 2018

Answer: The control A.10.1.1 - Policy on the use of cryptographic controls defines the guidelines for the use of cryptographic technologies in an organization (e.g., which technologies to use, when, by whom, etc.). So, if you have cryptographic technologies in your organization (like the SSL certificate) you have to consider the implementation of this control to treat risks like:
- IT staff implementing SSL in different ways in different places because there is no general rule about the issue,
- Unauthorized people accessing cryptographic technologies, because there is no list defining who can use it

To have an idea about how a cryptographic policy looks like, I suggest you to take a look at the free demo of o ur Policy on the Use of Cryptographic Controls at this link: https://advisera.com/27001academy/documentation/policy-on-the-use-of-encryption/

This article will provide you further explanation about control A.10.1.1:
- How to use the cryptography according to ISO 27001 control A.10 https://advisera.com/27001academy/how-to-use-the-cryptography-according-to-iso-27001/

These materials will also help you regarding control A.10.1.1:
- ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 31, 2018

Mar 31, 2018

Suggested Topics