Cybersecurity GRC 14 items
Encryption & Cryptographic Key Management Audit
Audits cryptographic controls and the key management lifecycle covering algorithms, key generation, storage, rotation, and destruction.
NIST 800-53ISO 27001:2022PCI DSS 4.0
Free PDF · enter your email to download.
Cryptographic Policy & Standards
- Is a documented cryptography and key management policy established? *
- Are only approved, strong algorithms used (e.g., AES-256, RSA-2048+, TLS 1.2+)? *
- Are deprecated protocols and ciphers (SSL, early TLS, MD5, SHA-1) disabled? *
Data Protection
- Is sensitive data encrypted at rest with approved algorithms? *
- Is data encrypted in transit over untrusted networks? *
- Is PAN rendered unreadable using strong cryptography where stored? *
Key Lifecycle Management
- Are keys generated using a secure, approved random number generator? *
- Are cryptographic keys stored in a hardware security module (HSM) or dedicated KMS? *
- Are keys rotated on a defined cryptoperiod? *
- Is access to keys restricted to the fewest custodians necessary? *
Key Rotation & Destruction
- Is there a documented procedure for retiring, replacing, or revoking compromised keys? *
- Are retired or expired keys securely destroyed? *
- Do key custodians formally acknowledge their key-handling responsibilities? *
- When were production data-encryption keys last rotated?
Download the full Encryption & Cryptographic Key Management Audit checklist
Get it as a clean, printable PDF — free.
