A.2 Encryption Standards

Version: April 2025
Aligned with: ISO/IEC 27001:2022 (Annex A: A.8.24)
Applies to: All employees, contractors, and systems handling sensitive or regulated data

Purpose
To define encryption requirements for data at rest and in transit, ensuring confidentiality and integrity of organizational information.

1. Data at Rest
(Aligned with A.8.24 – Use of cryptography)

  • AES-256 encryption for sensitive data storage
  • Full disk encryption for all mobile devices and laptops
  • Database encryption for sensitive information
  • Encrypted backups with separate key management

2. Data in Transit
(Aligned with A.8.24 – Use of cryptography)

  • TLS 1.3 minimum for all web communications
  • VPN encryption using IPSec or equivalent
  • Secure email encryption for sensitive communications
  • API communications must use HTTPS with certificate validation
Direct URL: