N.4.12 Cryptography and encryption
Control Overview
This control mandates that the organization establishes, implements, and enforces rules governing the use of cryptography to protect the confidentiality and integrity of information assets. Based on a structured risk assessment, encryption must be applied uniformly across two distinct states: data-in-transit (being transmitted over public or untrusted networks) and data-at-rest (stored on physical or logical media). Furthermore, the control demands strict operational lifecycle governance over cryptographic keys (KMS), standard-compliant digital certificates (TLS/HTTPS perimeters), and foundational email security protocols (such as SPF, DKIM, DMARC, and DNSSEC) to prevent eavesdropping, tampering, or domain spoofing.
Applicability Note: This control is fully applicable to the anDREa platform and serves as the primary technical mechanism for securing multi-tenant data silos and cloud communication vectors.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, embedding cryptographic guardrails natively into our cloud deployment models.
anDREa treats unencrypted data as an unacceptable operational risk. Our encryption framework covers the entire system lifecycle:
- Data-at-Rest: All data repositories within the myDRE environment (Microsoft Azure), Google Workspace, and supporting SaaS tools are systematically encrypted using industry-standard algorithms (such as AES-256). Key cycles rely on managed cloud-provider Key Management Services (KMS) and Platform Managed Keys (PMK) to guarantee separation of duties and secure key rotation. Cryptographic implementations for each individual asset type are detailed in our *Record of Processing Activities (ROPA)**.
- Data-in-Transit: Public internet perimeters are restricted to high-grade TLS/HTTPS configurations. Our policy mandates a minimum RSA key length of 2048 bits (or equivalent ECC curves) and enforces real-time tracking of certificate expiration dates to ensure seamless renewals.
- Email & Domain Hardening: All outbound and inbound communication routing channels undergo security scanning to verify active enforcement of DNSSEC, SPF, DKIM, and DMARC policies, preventing domain hijacking and phishing delivery.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.24 - Use of cryptography | Mandates that rules for the use of cryptography, including cryptographic key management, are defined and properly implemented. |
| Data Architecture | Record of Processing Activities (ROPA) | The official organizational ledger explicitly mapping each structural asset to its corresponding encryption-at-rest methodology. |
| Operational Validation | Periodic Security Controls | Automated and manual audit records showing routine configuration reviews of Google Workspace, Azure cloud fabric, GitHub, and production domains. |
| Public Perimeters | TLS/HTTPS Certificate Configurations | Cloud ingress edge metrics proving enforcement of modern cipher suites, standard key lengths 2048-bit), and active validity monitors. (Record of Processing Activities (ROPA)) |
| Domain Security | DNS Zone Records (SPF, DKIM, DMARC, DNSSEC) | Live public DNS deployment files proving cryptographic protection against email spoofing and domain routing alterations. (DNS & Domain Checks) |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Automated cloud-native KMS key management, universal data-at-rest encryption, robust TLS transmission profiles, and multi-layered email authentication controls are fully active, monitored via periodic controls, and auditable.