High Priority

Encryption Policy

Defines encryption requirements for data at rest, in transit, and cryptographic key management.

Core Security Policies 5-7 pages Updated 2025-01-10 Annual review
Included with All Packages

Get this document plus 100+ more with any security package.

View Security Packages

Starting at $1,997

About This Document

Specifies encryption standards and requirements for protecting sensitive data. Covers data at rest encryption, transport layer security, key management, and approved algorithms. Critical for protecting data confidentiality.

What's Included

  • Approved encryption algorithms
  • Data at rest encryption requirements
  • Data in transit encryption requirements
  • Key management procedures
  • Certificate management

Framework Compliance Mappings

This document helps satisfy the following compliance requirements:

SOC 2

SOC 2 Type II

CC6.1 CC6.7

ISO 27001

ISO/IEC 27001:2022

A.8.24

HIPAA

Health Insurance Portability and Accountability Act

164.312(a)(2)(iv) 164.312(e)(2)(ii)

PCI DSS

Payment Card Industry Data Security Standard 4.0.1

3.4 3.5 3.6 4.1

NIST

NIST Cybersecurity Framework 2.0

PR.DS-1 PR.DS-2 PR.DS-5

GDPR

General Data Protection Regulation

Art. 32

Who Needs This Document?

  • All organizations

Get Encryption Policy + 100 More Documents

Full document library included with any security package. Professional templates, framework-mapped, ready to customize.

View Security Packages