This Cryptographic Controls Policy details when encryption is required and how encryption keys (private and public) should be managed.It links to a Password Policy and Security Policy, which are typically other policies used as part of an overall Information Security Management System (ISMS), such as those required for ISO27001 and SOC2.