Skip to content

Cryptography Policy

Cryprography Policy

Version history

Version Number Date Description Created By Approved By
0.1 20/Oct/2023 Initial Copy [Name] [Name]
0.2 18/Jun/2024 Approved [Name] [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Introduction

The purpose of this policy is to ensure that Individual business units shall design and implement the cryptographic controls such that it appropriately safeguards all Information assets, Information data (In transit and at rest).

Scope

The scope of this policy and procedure is applicable to the management of all types of Cryptographic Keys used within tecciance.

Objectives

The objective of this policy is to provide management support and direction towards implementation and maintenance of cryptographic controls across tecciance.

Responsibilities

The primary ownership of implementing this policy lies with the IT, Finance, and Development Team.

Policy

Key Generation or Acquisition

Below types of Cryptographic Keys may be used within tecciance:

Cryptographic Key

Usage

SSL Certificate tecciance Website, tecciance Domain
TLS / SSL Encryption Emails - Gmail
Authentication Tokens & IMA AWS Admin Access, AWS User Access
VPN Encryption Key Users connecting to Servers
2 Factor Authentication GIT Repo & Click-Up
  • Cryptographic Keys may be either generated by tecciance or procured from a Third-Party Certifying Authority (CA).

  • When procuring from a Third-Party CA, requirements about encryption, its retention, etc., shall be considered.

  • When the Cryptographic Keys are generated by tecciance using Hardware or Software systems, appropriate encryption methods, technology, and levels shall be defined and followed.

  • Applicable legal, statutory, regulatory, or contractual obligations shall be considered while deciding the requirements about encryption and keys.

  • Requirements for secure storage, handling, and retention of Keys shall be identified and defined for each type of Key.

Key Inventorying and Allocation

  • All types of cryptographic controls and keys shall be inventoried within the Asset Inventory.

  • Keys shall be allocated to Information Systems or Users, and records shall be maintained within the Click- up application.

  • Appropriate approvals shall be procured before allocating/handing over the keys to users/Departments. For each of the Keys issued or allocated, a Custodian shall be identified and assigned within the Asset Inventory. Keys, when required to be stored, shall be protected from unauthorized access, alteration, or tampering.

Key De-Allocation and Disposal

  • A Key, when expired or no longer required, shall be de-allocated from the information systems.

  • Expired or De-allocated Keys shall be collected back and either returned to the Certifying Authority or disposed of securely.

  • Records of the return or disposal of Keys shall be maintained.

Procedure

Types of Keys

  • Keys shall be either generated by tecciance using servers and systems or procured from a third-party

  • Certificate Authority (CA). All Keys generated or procured shall be inventoried using Asset Inventory. The inventorying should include minimum information about –

  • Key Name, Identification

  • Details of Certificate Authority (CA) if procured from CA Date of Generation / Procurement

  • Validity of Key / Expiry Date

  • Name of Person / Department who had custody of the Key.

  • Retention or Validity period for each type of Key shall be identified and applied to keys in possession of tecciance.

  • The expired keys shall be either returned to the vendor or CA or disposed/deleted using secure methods.

  • Records of Key returning to Vendor/CA or disposal shall be maintained for audit and reference purposes.

SSL Certificate Process

To procure an SSL Certificate from a Certificate Authority (CA) - Standard SSL:

  • Use the SSL wizard to request your certification.

  • Go to your GoDaddy product page.

  • Select Manage all next to SSL Certificates.

  • Select New Certificate for the SSL credit you want to use.

  • On the certification setup page, select choose a Domain.

  • Start typing your domain name.

  • Select one of your GoDaddy domains or enter the fill domain and then select continue.

Use the SSL Wizard to create a CSR and Private Key, and then request your certificate.

  • Go to your GoDaddy product page.

  • Select Manage All next to SSL Certificates.

  • Select New Certificate for the SSL credit you want to use.

  • Your Private Key and Certificate signing request (CSR) will appear below your domain name,

  • For both, select Save File and save a copy of your Private Key and CSR to a secure location.

  • That’s It! Your next step is to Prove you have control of the domain name,

Request your certificate with a CSR that has already been created.

  • Go to your GoDaddy product page.

  • Select Manage All next to SSL Certificates.

  • Select New Certificate for the SSL credit you want to use.

  • On the Certificate Setup page, select Input a CSR. Paste your CSR into the box and select Continue.

VPN Process

Tunnel, please refer to

Terms and Definitions

Following are the explanations of various terms used within this document:

Terms Definition
ISMS
  • Information Security Management System

Information Security
  • Confidentiality, Integrity, Availability of Information

CEO
  • Chief Executive Officer

LT
  • Leadership Team

IST
  • Information Security Team

Cryptography
  • Is a technique of securing information and communication using codes so that only those persons for whom the information is intended can understand it and process it, thus preventing unauthorized access to information. Features of cryptography include Confidentiality, Integrity, Non-repudiation, and Authentication.

Key
  • In cryptography, a key is a piece of information (a parameter) that determines the functional output of a cryptographic algorithm. For encryption algorithms, a key specifies the transformation of plaintext into ciphertext, and vice versa for decryption algorithms.

Certificate
  • A Digital Certificate is an electronic "password" that allows a person or organization to exchange data securely over the Internet using the public key infrastructure (PKI). A Digital Certificate is also known as a public key certificate or identity certificate. A digital certificate is a file that ensures the holder's identity and provides security. It is generated by a CA (Certifying Authority) and follows the X.509 standard format.

Digital Signature
  • A digital signature is used to verify authenticity, integrity, and non-repudiation.

VPN
  • Virtual Private Network - A virtual private network (VPN) is a technology that creates a safe and encrypted connection over a less secure network, such as the internet. It makes use of tunneling protocols to establish a secure connection.

**

Reference

  • Template – Asset Inventory

  • Asset Management Policy

  • Records of Key Generation, Storage, Allocation, De-Allocation and Disposal

Artificial intelligence, software agents, and organizational knowledge

This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.

Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.

Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.

AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.

Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.

Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.

Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.

HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.

Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.

Data in prompts, embeddings, and agent skill files follows the same cryptographic classification as the source records.