simpl.
Cybersecurity GRC 14 items

Encryption & Cryptographic Key Management Audit

Audits cryptographic controls and the key management lifecycle covering algorithms, key generation, storage, rotation, and destruction.

NIST 800-53ISO 27001:2022PCI DSS 4.0

Free PDF · enter your email to download.

Cryptographic Policy & Standards

  • Is a documented cryptography and key management policy established? *
  • Are only approved, strong algorithms used (e.g., AES-256, RSA-2048+, TLS 1.2+)? *
  • Are deprecated protocols and ciphers (SSL, early TLS, MD5, SHA-1) disabled? *

Data Protection

  • Is sensitive data encrypted at rest with approved algorithms? *
  • Is data encrypted in transit over untrusted networks? *
  • Is PAN rendered unreadable using strong cryptography where stored? *

Key Lifecycle Management

  • Are keys generated using a secure, approved random number generator? *
  • Are cryptographic keys stored in a hardware security module (HSM) or dedicated KMS? *
  • Are keys rotated on a defined cryptoperiod? *
  • Is access to keys restricted to the fewest custodians necessary? *

Key Rotation & Destruction

  • Is there a documented procedure for retiring, replacing, or revoking compromised keys? *
  • Are retired or expired keys securely destroyed? *
  • Do key custodians formally acknowledge their key-handling responsibilities? *
  • When were production data-encryption keys last rotated?

Download the full Encryption & Cryptographic Key Management Audit checklist

Get it as a clean, printable PDF — free.