Cryptography Policy
01 Jan 2022
To ensure the proper and effective use of cryptography to protect the confidentiality, authenticity, and integrity of Kwanso information. This policy establishes requirements for the use of cryptographic controls and for the management of cryptographic keys throughout their entire lifecycle.
All Kwanso information systems that store or transmit confidential data as defined in the Kwanso Data Management Policy. This policy applies to all employees of Kwanso and to all external parties who develop, operate, or manage information systems on Kwanso's behalf.
Kwanso shall evaluate the risks inherent in processing and storing data and shall implement cryptographic controls to mitigate those risks where deemed appropriate. Where encryption is in use, strong cryptography with associated key management processes and procedures shall be implemented and documented. All encryption shall be performed in accordance with industry standards, including NIST SP 800-57.
For all personal data, Kwanso shall consider the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, and shall implement appropriate technical and organizational measures surrounding the pseudonymization and encryption of data to ensure a level of security appropriate to the risk.
For all web traffic containing confidential data sent over the public Internet, the TLS v1.2 protocol or better must be utilized.
Access to cryptographic keys and secrets shall be tightly controlled in accordance with the Kwanso Access Control Policy. Cryptographic keys shall be protected against unauthorized access, use, disclosure, modification, loss, and destruction throughout their lifecycle, including generation, distribution, storage, rotation, and retirement.
The following table sets out the recommended usage for cryptographic keys:
Up to 2 years for normal certificates; up to 10 years for root certificates.
Bcrypt, PBKDF2, scrypt, or ECDH
Requests for an exception to this Policy must be submitted to the IT Manager for approval.
Any known violations of this policy should be reported to the IT Manager. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.