A.8.24 Technological
Use of cryptography
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- SC-12mostlyaligns with — Both controls establish requirements for the full lifecycle management of cryptographic keys, including generation, distribution, storage, rotation, revocation, recovery, and destruction.
- SC-13mostlyaligns with — Both controls require organizations to select and apply approved cryptographic algorithms and mechanisms that match the sensitivity of the information being protected.
- CM-6partialaligns with — Both controls require the organization to define and enforce approved cryptographic standards, algorithms, and configuration settings.
- SC-28partialaligns with — Both controls require cryptographic protection for information at rest on endpoint devices and storage media.
- SC-8partialaligns with — Both controls address the use of cryptography to protect the confidentiality and integrity of information transmitted over networks.
Aligned NIST CSF 2.0 outcomes (11)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.DS-01mostlyaligns with — The control establishes cryptographic mechanisms and key-management processes that directly protect the confidentiality and integrity of data at rest on endpoints and storage media.
- PR.DS-02mostlyaligns with — The control mandates the use of approved cryptographic algorithms and key handling to protect data transmitted over networks to mobile devices and storage media.
- GV.PO-01partialaligns with — The control explicitly calls for a topic-specific policy on cryptography that is derived from organizational context and risk priorities.
- GV.SC-05partialaligns with — The control requires that contracts and SLAs with external cryptographic-service providers address liability, reliability, and response times, thereby embedding cryptographic requirements into supplier agreements.
- ID.RA-09partialaligns with — The control’s emphasis on selecting approved cryptographic solutions and assessing their strength supports the authenticity and integrity evaluation of software and hardware prior to acquisition.
- PR.PS-01partialaligns with — The control requires an organization-wide policy and approved standards for cryptographic algorithms and usage, which are foundational elements of configuration management.
Related OWASP ASVS 5.0 requirements (12)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V11.1.1mostlycovers — The ISO control's requirement for a documented cryptographic policy and lifecycle directly implements the ASVS mandate for a documented key-management policy and lifecycle.
- V11.1.2mostlycovers — Mandating an inventory of algorithms, keys and certificates satisfies the ASVS requirement to maintain and regularly update a cryptographic inventory.
- V11.2.1partialaligns with — Specifying approved algorithms, cipher strength and usage practices aligns with the ASVS requirement to use industry-validated cryptographic implementations.
- V11.2.2partialaligns with — The ISO control's emphasis on standards, approved algorithms and key-management procedures supports the ASVS goal of designing for crypto-agility.
- V13.3.1partialaligns with — Requiring secure generation, storage, distribution and destruction of keys aligns with the ASVS requirement to use a secrets-management solution for cryptographic material.
- V13.3.4partialaligns with — Defining key rotation, revocation and archival processes aligns with the ASVS requirement that secrets be configured to expire and be rotated according to documented policy.
Related weaknesses / CWE (166)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-313fullprevents — Cryptography control directly mandates encryption of sensitive data at rest.
- CWE-314fullprevents — Cryptographic controls directly prevent cleartext storage of sensitive registry data.
- CWE-315fullprevents — Mandates use of cryptography to protect sensitive data, directly preventing cleartext cookie storage.
- CWE-329fullprevents — Mandates proper cryptographic controls including IV generation, directly preventing predictable-IV CBC weaknesses.
- CWE-5fullprevents — Directly requires use of cryptography to protect data confidentiality and integrity during transmission.
- CWE-1204mostlyprevents — Mandates correct use of cryptography, directly requiring strong, unpredictable IV generation for primitives that need it.
- CWE-1240mostlyprevents — Mandates approved cryptographic controls, directly preventing use of risky or non-compliant implementations.
- CWE-1394mostlyprevents — Mandates proper key management, directly preventing use of default cryptographic keys.
- CWE-256mostlyprevents — Requires use of cryptography to protect sensitive data such as passwords at rest.
- CWE-261mostlyprevents — Requires appropriate use of cryptography, indirectly discouraging weak encoding schemes.
- CWE-294mostlyprevents — Cryptographic protections (e.g., nonces, timestamps, message authentication codes) make captured authentication messages unusable for replay.
- CWE-296mostlyprevents — Mandates proper use of cryptography including certificate validation and trusted roots.
- CWE-299mostlyprevents — Mandates use of cryptography including certificate validation and revocation checking.
- CWE-300mostlyprevents — Cryptography provides channel integrity and can support endpoint authentication.
- CWE-318mostlyprevents — Cryptographic controls directly prevent cleartext storage of sensitive data in executables.
- CWE-322mostlyprevents — Use of cryptography mandates authenticated key-exchange mechanisms, directly addressing the lack of entity authentication.
- CWE-323mostlyprevents — Mandates proper cryptographic key and nonce management, directly preventing nonce/key-pair reuse.
- CWE-324mostlyprevents — Use-of-cryptography control explicitly covers key lifecycle management including expiration and rotation.
- CWE-327mostlyprevents — Mandating approved algorithms, cipher strength and usage standards directly stops the selection of broken or weak cryptographic primitives that attackers can exploit.
- CWE-328mostlyprevents — Mandates use of approved cryptographic algorithms, directly preventing weak-hash selection.
- CWE-330mostlyprevents — Cryptographic controls require use of approved, sufficiently random values for keys and nonces.
- CWE-331mostlyprevents — Mandates use of cryptography that must rely on sufficient entropy sources.
- CWE-334mostlyprevents — Cryptographic controls require adequate key/seed entropy, directly mitigating small random-value spaces.
- CWE-338mostlyprevents — Mandates use of approved cryptographic controls, directly requiring cryptographically strong RNGs.
- CWE-340mostlyprevents — Cryptographic controls require use of approved, sufficiently random algorithms and key-generation methods, directly mitigating predictable number/identifier weaknesses.
- CWE-341mostlyprevents — Cryptographic controls replace predictable values with high-entropy, non-guessable material.
- CWE-353mostlyprevents — Cryptographic controls can provide integrity verification for transmitted data.
- CWE-354mostlyprevents — Cryptographic controls mandate integrity mechanisms whose correct validation directly prevents CWE-354.
- CWE-522mostlyprevents — Protecting secret and private keys against disclosure and unauthorized use decreases the exposure of credentials that are stored or transmitted in recoverable form.
- CWE-523mostlyprevents — Requires use of cryptography, directly enabling encryption of credentials in transit.
- CWE-526mostlyprevents — Cryptography control directly addresses the lack of encryption for sensitive data stored in environment variables.
- CWE-656mostlyprevents — Mandates use of cryptography whose strength is independent of secrecy of design or keys.
- CWE-759mostlyprevents — Use of cryptography requires appropriate cryptographic controls including salting for password hashing.
- CWE-760mostlyprevents — Use of cryptography requires appropriate cryptographic controls including proper salting, largely mitigating predictable-salt weaknesses.
- CWE-780mostlyprevents — Mandates proper use of cryptography, directly requiring OAEP with RSA.
- CWE-924mostlyprevents — Cryptography is the primary technical means to enforce message integrity during transmission.
- CWE-1241partialprevents — Mandates use of approved cryptographic algorithms and RNGs, directly preventing predictable PRNGs.
- CWE-1255partialmitigates — Cryptographic implementation guidance can require constant-time or masked algorithms that reduce power side-channel leakage during token comparison.
- CWE-1270partialprevents — Proper use of cryptography ensures tokens are generated with correct algorithms, keys and entropy.
- CWE-1279partialprevents — Mandates proper use of cryptography, which includes ensuring supporting units are ready before operations.
- CWE-1291partialprevents — Cryptographic key-management rules would normally require separate keys for debug vs. production signing.
- CWE-1323partialprevents — Cryptography can be applied to encrypt trace data at rest or in transit.
- CWE-202partialmitigates — Cryptography can protect data at rest or in transit, limiting exposure even if inference occurs.
- CWE-260partialmitigates — Cryptographic controls can protect stored credentials, but do not address the root practice of embedding passwords in files.
- CWE-290partialprevents — Cryptography supports authentication but does not guarantee correct implementation against spoofing.
- CWE-295partialprevents — Requiring issuance and validation of public-key certificates under an approved policy reduces the chance that certificates with improper validation will be trusted.
- CWE-297partialprevents — Use of cryptography mandates correct implementation of certificate validation and hostname verification.
- CWE-298partialprevents — Cryptography policy requires proper certificate lifecycle management including expiration validation.
- CWE-301partialprevents — Cryptographic controls can underpin stronger authentication protocols but do not by themselves prevent reflection attacks.
- CWE-316partialprevents — Cryptographic controls can mandate encryption of sensitive data in memory, directly reducing cleartext exposure.
- CWE-317partialprevents — Cryptography can protect data at rest/display, but does not mandate GUI-level masking.
- CWE-321partialprevents — Key-management controls that govern generation, rotation and protection of keys make the use of embedded hard-coded cryptographic keys less likely and easier to detect.
- CWE-326partialprevents — Requiring the organization to define and enforce minimum cryptographic strength prevents deployment of insufficient key lengths or weak ciphers that can be brute-forced.
- CWE-332partialprevents — Mandates use of cryptography that must rely on cryptographically strong RNGs, directly addressing insufficient entropy.
- CWE-333partialprevents — Mandates proper cryptographic key generation and entropy sources, directly addressing insufficient TRNG entropy.
- CWE-335partialprevents — Cryptography policy and key-management rules directly require proper seeding of PRNGs used for keys and nonces.
- CWE-336partialprevents — Cryptography policy and key-management requirements directly mandate proper PRNG seeding and entropy sources.
- CWE-337partialprevents — Mandates use of cryptography, which includes selecting and seeding PRNGs with sufficient entropy.
- CWE-339partialprevents — Mandates use of cryptography that must rely on cryptographically strong PRNGs with adequate seed entropy.
- CWE-342partialprevents — Cryptographic controls require use of approved, unpredictable RNGs, directly mitigating predictable-value weaknesses.
- CWE-343partialprevents — Cryptographic controls require use of approved, unpredictable RNGs, directly mitigating predictable value sequences.
- CWE-345partialprevents — Cryptographic mechanisms directly verify data origin and integrity, preventing acceptance of unauthentic data.
- CWE-347partialprevents — Establishing approved cryptographic solutions and usage practices lowers the probability that signature-verification steps will be omitted or incorrectly implemented.
- CWE-358partialprevents — Use of cryptography control depends on correct implementation of standardized cryptographic checks.
- CWE-360partialprevents — Cryptography can protect event integrity and authenticity but is not explicitly required by the control for this purpose.
- CWE-370partialmitigates — Use of cryptography includes certificate lifecycle management, yet does not mandate continuous revocation status verification.
- CWE-419partialprevents — Cryptography can protect confidentiality and integrity of the primary channel.
- CWE-524partialmitigates — Cryptography can protect cached data at rest, but does not address access control scope.
- CWE-555partialprevents — Requires cryptographic protection of sensitive data, which can mitigate plaintext password storage when applied to credentials.
- CWE-599partialprevents — Mandates proper use of cryptography including certificate validation, directly addressing the missing SSL_get_verify_result() check.
- CWE-614partialmitigates — Use of cryptography control mandates encryption in transit, which HTTPS provides, but does not specifically require the Secure cookie attribute.
- CWE-649partialprevents — Cryptographic controls must include integrity mechanisms (e.g., MACs, signatures) to detect tampering of protected data.
- CWE-757partialprevents — Mandates use of strong, approved cryptographic algorithms, directly preventing downgrade to weaker ones.
- CWE-798partialmitigates — Secure key-generation, distribution and storage procedures reduce the likelihood that hard-coded or default cryptographic keys will be introduced or left unprotected.
- CWE-916partialprevents — Requires appropriate use of cryptography, which encompasses selecting strong hashing algorithms for passwords.
- CWE-923partialprevents — Cryptography can protect channels but does not guarantee correct endpoint identity without additional controls.
- CWE-940partialprevents — Cryptography can support channel authentication but does not inherently verify source without proper implementation.
- CWE-1230nonemitigates — Cryptographic controls can protect metadata confidentiality, but the control is broader in scope.
- CWE-1258nonenone — Cryptographic key management and secure handling requirements reduce exposure of sensitive values during debug entry.
- CWE-1259nonenone — Cryptography can protect token confidentiality but does not address improper assignment logic.
- CWE-1283nonenone — Cryptographic integrity mechanisms can protect attestation data from unauthorized modification.
- CWE-1300nonenone — Cryptographic implementations may incorporate countermeasures against side-channel leakage.
- CWE-1326nonemitigates — Cryptographic controls can protect the root of trust but do not mandate its hardware immutability.
- CWE-257nonemitigates — Requires proper use of cryptography, which can mitigate recoverable storage if applied correctly to passwords.
- CWE-303nonenone — Cryptography control addresses proper use of authentication algorithms but is broader than authentication alone.
- CWE-325nonenone — Mandates correct use of cryptographic controls, directly preventing omission of required algorithm steps.
- CWE-346nonemitigates — Cryptography can support origin validation when used for authentication but is not the control's primary intent.
- CWE-348nonemitigates — Cryptographic controls can verify source authenticity and integrity, thereby mitigating the weakness.
- CWE-385nonenone — Cryptography can mask data but does not inherently stop timing side-channels.
- CWE-402nonemitigates — Cryptography can protect data in transit but does not stop the product from sending it to the wrong party.
- CWE-420nonemitigates — Cryptography can protect alternate channels but does not address the policy of applying equal protection across channels.
- CWE-514nonenone — Cryptography can mask or eliminate some covert channels, but the control itself does not mandate covert-channel analysis.
- CWE-515nonenone — Cryptography can protect data in transit/storage but does not prevent covert storage channels within a system.
- CWE-539nonenone — Cryptographic controls can mandate encryption of sensitive data stored in cookies.
- CWE-591nonenone — Cryptographic controls can reduce exposure of sensitive data even if it is paged, but do not directly enforce memory locking.
- CWE-598nonenone — Cryptography controls encourage TLS to protect query strings in transit.
- CWE-836nonenone — Requires proper cryptographic practices for protecting passwords, indirectly mitigating misuse of hashes in authentication.
Mitigated MITRE ATT&CK techniques (7)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1040mostlyprevents — Requiring encryption of data in transit and proper key protection reduces the value an attacker gains from passively capturing network packets.
- T1557mostlyprevents — Mandating approved cryptographic algorithms and key-management procedures for network traffic makes it harder for an adversary to intercept and manipulate traffic in order to steal credentials.
- T1539partialmitigates — Mandating encryption and secure key handling for web sessions and tokens reduces the attacker’s ability to capture and replay session cookies or tokens in cleartext.
- T1552partialprevents — Enforcing encryption of sensitive information on endpoints and storage media limits an attacker’s ability to locate and read credentials stored in files or configuration stores.
- T1003nonemitigates — Requiring cryptographic protection of credential stores and proper key-management practices reduces the feasibility of dumping and decrypting authentication material from memory or disk.
- T1027nonemitigates — Specifying approved cipher strengths and forbidding weak or deprecated algorithms makes it more difficult for adversaries to hide payloads behind weak or custom encryption schemes.
- T1573nonemitigates — Requiring the use of vetted cryptographic algorithms and key-management controls limits an attacker’s ability to establish encrypted command-and-control channels that evade detection.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A04fullprevents — Mandating approved algorithms, key strength, and lifecycle controls directly eliminates weak or missing encryption that would otherwise expose sensitive data in transit or at rest.
- A02mostlyprevents — Requiring a documented cryptography policy and approved standards prevents ad-hoc or misconfigured use of crypto that commonly leads to insecure defaults or inconsistent settings across systems.
- A08mostlyprevents — Secure key generation, distribution, revocation, and destruction processes reduce the chance that tampered or leaked keys will allow undetected modification of encrypted data or software artifacts.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.