ISO 27001 8.24 Use of Cryptography Requirement:
"Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented."[1]
ISO 27001 8.24 Use of Cryptography Requirement Explanation:
The organization should define what types of encryption will be used to protect information on its systems. For example it can define that BitLocker and File vault will be used to encrypt information on workstations and removable storage devices and that the keys will be managed using Microsoft Intune. Other types of cryptographic keys that need to be managed include digital certificates and SSH keys.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you