Encryption policy

The purpose of an encryption policy is to establish, at a senior management level, the business and compliance expectations that the organization needs to meet. The policy serves as a starting point to define a suitable encryption strategy. The policy should be abstract enough to provide freedom and flexibility for implementation. At the same time, it must be specific enough to define the confines of an acceptable implementation that meets organizational objectives. In general, policies are technology-agnostic and very infrequently changed because they define the fundamental characteristics of your enterprise encryption strategy.

Typically, encryption policies contain, but are not limited to, the following:

The highest management level of the organization, such as the CIO, CTO, and CISO, usually define and approve the encryption policy.

Consider the following when creating your encryption policy: