Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What is the difference between a cryptography policy…
Governance, Ownership & Risk

What is the difference between a cryptography policy and a managed key lifecycle in ISO 27001?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

A cryptography policy defines the rules for using encryption, such as approved algorithms, key lengths, and when encryption is required. A managed key lifecycle is the operating process that handles each key from creation to destruction. ISO 27001 expects both, because policy sets intent while lifecycle evidence shows whether cryptography is actually controlled.

Why cryptography policy and managed key lifecycle are different controls

A cryptography policy is a decision framework. It tells teams which cryptographic methods are approved, where encryption is required, and what minimum strength is acceptable. A managed key lifecycle is the operating discipline behind those decisions. It proves keys are created, protected, rotated, retired, and destroyed in a controlled way, rather than simply being allowed to exist indefinitely.

The distinction matters because a policy can be written once and then ignored in practice. Lifecycle management is where cryptography becomes auditable: who can generate keys, how they are stored, when they expire, and whether old material is revoked before it can still unlock data or sign trusted objects. That operational evidence is what turns an abstract rule into control assurance.

In ISO/IEC 27001, the policy answers “what should happen,” while the lifecycle answers “how it is actually being handled.” A strong programme needs both. The policy gives consistency across teams and systems, while lifecycle evidence shows whether implementation matches the rule set, especially where keys support authentication, data protection, signing, or encryption at scale. ISO/IEC 27001:2022 Information Security Management

What each one governs in practice

Cryptography policy sits at the governance layer. It typically covers approved algorithms, minimum key lengths, certificate and cipher preferences, approved use cases, and exceptions. It is the document teams rely on when deciding whether a design is acceptable before deployment.

Managed key lifecycle sits at the control-operation layer. It covers key generation, escrow where used, secure storage, distribution, rotation, replacement, revocation, backup, recovery, and destruction. If policy is the rulebook, lifecycle is the set of processes and records that prove the rulebook is being followed.

That is why lifecycle management is usually more visible during audits than the policy itself. A policy can say keys must be rotated, but the lifecycle shows whether rotation actually happens, whether expired keys are still active, and whether orphaned material remains in systems after ownership changes. For key lifecycle specifics, the clearest technical reference is NIST SP 800-57 Key Management.

How ISO 27001 uses both to show control maturity

iso 27001 does not treat cryptography as a paper exercise. It expects organisations to define cryptographic rules and to operate them consistently. The practical difference is that policy helps you choose suitable cryptography, while managed lifecycle helps you demonstrate control over the cryptographic material itself.

For practitioners, that means the policy should be specific enough to prevent ad hoc crypto choices, but not so vague that every team interprets it differently. The lifecycle should be specific enough to show ownership, rotation cadence, revocation triggers, and secure destruction. A policy without lifecycle is easy to approve and hard to trust. A lifecycle without policy is operationally busy, but lacks a clear standard for what “correct” means.

That is also why ISO 27001 assessments often look for evidence such as key inventories, rotation records, certificate expiry tracking, exception handling, and destruction attestations. Those artefacts show the control is operating, not merely documented. Broader guidance in ISO/IEC 27002:2022 Information Security Controls helps translate the policy intent into implementable control practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-57 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.8.24 — Use of cryptographyDefines governance for approved cryptographic use in the ISMS.
A.8.25 — Key managementDirectly covers managed key lifecycle and key handling controls.
A.5.15 — Access controlCryptographic keys often protect access and need governed authorization.
Recommendation — Define approved cryptographic methods and required use cases for the environment. Implement controlled key generation, rotation, storage, revocation, and destruction. Restrict who can administer and use keys that protect sensitive systems and data.
NIST SP 800-57Key management lifecycle guidanceMaterially explains key lifecycle, cryptoperiods, and lifecycle protection.
Recommendation — Apply lifecycle guidance to define rotation, protection, and retirement rules for keys.

Practitioner Guidance

What to verify: Check whether the cryptography policy names concrete standards, exceptions, and approval authority, and whether the key lifecycle has measurable operational evidence such as rotation logs, expiry monitoring, and destruction records. If either side is missing, the control is incomplete even if the other looks strong.

Decision rule: If you are preparing for audit or remediation, treat lifecycle evidence as the higher-value test of control effectiveness. If the organisation cannot show what happened to keys over time, the policy should be treated as intent, not assurance.

Practitioner takeaway: In ISO 27001, policy establishes the expected cryptographic posture, but managed key lifecycle is what proves the organisation can actually govern cryptographic trust over time.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org