Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Solution Architect

previous version on gdrive

N.4.12 Cryptography and encryption

Control Overview

This control mandates that the organization establishes, implements, and enforces rules governing the use of cryptography to protect the confidentiality and integrity of information assets. Based on a structured risk assessment, encryption must be applied uniformly across two distinct states: data-in-transit (being transmitted over public or untrusted networks) and data-at-rest (stored on physical or logical media). Furthermore, the control demands strict operational lifecycle governance over cryptographic keys (KMS), standard-compliant digital certificates (TLS/HTTPS perimeters), and foundational email security protocols (such as SPF, DKIM, DMARC, and DNSSEC) to prevent eavesdropping, tampering, or domain spoofing.

note

Applicability Note: This control is fully applicable to the anDREa platform and serves as the primary technical mechanism for securing multi-tenant data silos and cloud communication vectors.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, embedding cryptographic guardrails natively into our cloud deployment models.

anDREa treats unencrypted data as an unacceptable operational risk. Our encryption framework covers the entire system lifecycle:

  • Data-at-Rest: All data repositories within the myDRE environment (Microsoft Azure), Google Workspace, and supporting SaaS tools are systematically encrypted using industry-standard algorithms (such as AES-256). Key cycles rely on managed cloud-provider Key Management Services (KMS) and Platform Managed Keys (PMK) to guarantee separation of duties and secure key rotation. Cryptographic implementations for each individual asset type are detailed in our *Record of Processing Activities (ROPA)**.
  • Data-in-Transit: Public internet perimeters are restricted to high-grade TLS/HTTPS configurations. Our policy mandates a minimum RSA key length of 2048 bits (or equivalent ECC curves) and enforces real-time tracking of certificate expiration dates to ensure seamless renewals.
  • Email & Domain Hardening: All outbound and inbound communication routing channels undergo security scanning to verify active enforcement of DNSSEC, SPF, DKIM, and DMARC policies, preventing domain hijacking and phishing delivery.

Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.24 - Use of cryptographyMandates that rules for the use of cryptography, including cryptographic key management, are defined and properly implemented.
Data ArchitectureRecord of Processing Activities (ROPA)The official organizational ledger explicitly mapping each structural asset to its corresponding encryption-at-rest methodology.
Operational ValidationPeriodic Security ControlsAutomated and manual audit records showing routine configuration reviews of Google Workspace, Azure cloud fabric, GitHub, and production domains.
Public PerimetersTLS/HTTPS Certificate ConfigurationsCloud ingress edge metrics proving enforcement of modern cipher suites, standard key lengths 2048-bit), and active validity monitors. (Record of Processing Activities (ROPA))
Domain SecurityDNS Zone Records (SPF, DKIM, DMARC, DNSSEC)Live public DNS deployment files proving cryptographic protection against email spoofing and domain routing alterations. (DNS & Domain Checks)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Automated cloud-native KMS key management, universal data-at-rest encryption, robust TLS transmission profiles, and multi-layered email authentication controls are fully active, monitored via periodic controls, and auditable.