Cryptography Policy

Cryptography Policy

Cryptography Policy
Policy Owner: Kwanso LLC
Effective Date: 01 Jan 2022

Purpose

To ensure the proper and effective use of cryptography to protect the confidentiality, authenticity, and integrity of Kwanso information. This policy establishes requirements for the use of cryptographic controls and for the management of cryptographic keys throughout their entire lifecycle.

Scope

All Kwanso information systems that store or transmit confidential data as defined in the Kwanso Data Management Policy. This policy applies to all employees of Kwanso and to all external parties who develop, operate, or manage information systems on Kwanso's behalf.

Policy

Kwanso shall evaluate the risks inherent in processing and storing data and shall implement cryptographic controls to mitigate those risks where deemed appropriate. Where encryption is in use, strong cryptography with associated key management processes and procedures shall be implemented and documented. All encryption shall be performed in accordance with industry standards, including NIST SP 800-57.
For all personal data, Kwanso shall consider the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, and shall implement appropriate technical and organizational measures surrounding the pseudonymization and encryption of data to ensure a level of security appropriate to the risk.
For all web traffic containing confidential data sent over the public Internet, the TLS v1.2 protocol or better must be utilized.

Key Management

Access to cryptographic keys and secrets shall be tightly controlled in accordance with the Kwanso Access Control Policy. Cryptographic keys shall be protected against unauthorized access, use, disclosure, modification, loss, and destruction throughout their lifecycle, including generation, distribution, storage, rotation, and retirement.
The following table sets out the recommended usage for cryptographic keys:
Title
Title
Title
Title
Title
Domain
Key Type
Algorithm
Key Length
Max Expiration
Web Certificate
Digital Signature PKCS#1
DSA or RSA
2048 bit
Up to 2 years for normal certificates; up to 10 years for root certificates.
Web Cipher
Encryption
AES
256 bit
N/A
Confidential Data
Encryption
AES
256 bit
1 Year
Password
Hash
Bcrypt, PBKDF2, scrypt, or ECDH
256 bit + 10K Stretch
N/A
Laptop HDD
Encryption
AES
128 or 256 bit
N/A

Exceptions

Requests for an exception to this Policy must be submitted to the IT Manager for approval.

Violations & Enforcement

Any known violations of this policy should be reported to the IT Manager. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.
Title
Title
Title
Title
Title
Version
Date
Description
Author
Approved by
1.0
01-Jan-2022
First Version
Fakhar Hussain
Umair Siddique