Cryptography Policy¶
Cryprography Policy
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 20/Oct/2023 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Introduction¶
The purpose of this policy is to ensure that Individual business units shall design and implement the cryptographic controls such that it appropriately safeguards all Information assets, Information data (In transit and at rest).
Scope¶
The scope of this policy and procedure is applicable to the management of all types of Cryptographic Keys used within tecciance.
Objectives¶
The objective of this policy is to provide management support and direction towards implementation and maintenance of cryptographic controls across tecciance.
Responsibilities¶
The primary ownership of implementing this policy lies with the IT, Finance, and Development Team.
Policy¶
Key Generation or Acquisition¶
Below types of Cryptographic Keys may be used within tecciance:
|
|
|---|---|
| SSL Certificate | tecciance Website, tecciance Domain |
| TLS / SSL Encryption | Emails - Gmail |
| Authentication Tokens & IMA | AWS Admin Access, AWS User Access |
| VPN Encryption Key | Users connecting to Servers |
| 2 Factor Authentication | GIT Repo & Click-Up |
-
Cryptographic Keys may be either generated by tecciance or procured from a Third-Party Certifying Authority (CA).
-
When procuring from a Third-Party CA, requirements about encryption, its retention, etc., shall be considered.
-
When the Cryptographic Keys are generated by tecciance using Hardware or Software systems, appropriate encryption methods, technology, and levels shall be defined and followed.
-
Applicable legal, statutory, regulatory, or contractual obligations shall be considered while deciding the requirements about encryption and keys.
-
Requirements for secure storage, handling, and retention of Keys shall be identified and defined for each type of Key.
Key Inventorying and Allocation¶
-
All types of cryptographic controls and keys shall be inventoried within the Asset Inventory.
-
Keys shall be allocated to Information Systems or Users, and records shall be maintained within the Click- up application.
-
Appropriate approvals shall be procured before allocating/handing over the keys to users/Departments. For each of the Keys issued or allocated, a Custodian shall be identified and assigned within the Asset Inventory. Keys, when required to be stored, shall be protected from unauthorized access, alteration, or tampering.
Key De-Allocation and Disposal¶
-
A Key, when expired or no longer required, shall be de-allocated from the information systems.
-
Expired or De-allocated Keys shall be collected back and either returned to the Certifying Authority or disposed of securely.
-
Records of the return or disposal of Keys shall be maintained.
Procedure¶
Types of Keys¶
-
Keys shall be either generated by tecciance using servers and systems or procured from a third-party
-
Certificate Authority (CA). All Keys generated or procured shall be inventoried using Asset Inventory. The inventorying should include minimum information about –
-
Key Name, Identification
-
Details of Certificate Authority (CA) if procured from CA Date of Generation / Procurement
-
Validity of Key / Expiry Date
-
Name of Person / Department who had custody of the Key.
-
Retention or Validity period for each type of Key shall be identified and applied to keys in possession of tecciance.
-
The expired keys shall be either returned to the vendor or CA or disposed/deleted using secure methods.
-
Records of Key returning to Vendor/CA or disposal shall be maintained for audit and reference purposes.
SSL Certificate Process¶
To procure an SSL Certificate from a Certificate Authority (CA) - Standard SSL:
-
Use the SSL wizard to request your certification.
-
Go to your GoDaddy product page.
-
Select Manage all next to SSL Certificates.
-
Select New Certificate for the SSL credit you want to use.
-
On the certification setup page, select choose a Domain.
-
Start typing your domain name.
-
Select one of your GoDaddy domains or enter the fill domain and then select continue.
Use the SSL Wizard to create a CSR and Private Key, and then request your certificate.¶
-
Go to your GoDaddy product page.
-
Select Manage All next to SSL Certificates.
-
Select New Certificate for the SSL credit you want to use.
-
Your Private Key and Certificate signing request (CSR) will appear below your domain name,
-
For both, select Save File and save a copy of your Private Key and CSR to a secure location.
-
That’s It! Your next step is to Prove you have control of the domain name,
Request your certificate with a CSR that has already been created.¶
-
Go to your GoDaddy product page.
-
Select Manage All next to SSL Certificates.
-
Select New Certificate for the SSL credit you want to use.
-
On the Certificate Setup page, select Input a CSR. Paste your CSR into the box and select Continue.
VPN Process¶
-
Procedure for generating OpenVPN Certificates and Keys
-
Procedure for configuring a VPN using Easy VPN and IPSEC
Tunnel, please refer to
-
https://www.cisco.com/en/US/docs/routers/access/800/850/software/configuration/guide/vpnezvpn.html
-
Procedure for creating Client VPN on AWS
-
Please refer to https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/cvpn-getting-started.html
Terms and Definitions¶
Following are the explanations of various terms used within this document:
| Terms | Definition |
|---|---|
| ISMS |
|
| Information Security |
|
| CEO |
|
| LT |
|
| IST |
|
| Cryptography |
|
| Key |
|
| Certificate |
|
| Digital Signature |
|
| VPN |
|
**
Reference¶
-
Template – Asset Inventory
-
Asset Management Policy
-
Records of Key Generation, Storage, Allocation, De-Allocation and Disposal
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.
Data in prompts, embeddings, and agent skill files follows the same cryptographic classification as the source records.