Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.13.11Cryptographic protectionITSP.10.171System and communications protection

Official Requirement

Implement the following types of cryptography when used to protect the confidentiality of specified information: [Assignment: organization-defined types of cryptography].

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

When cryptography is used to protect sensitive information, your organization must use the defined cryptographic types and algorithms (FIPS-validated is recommended). This means ensuring that encryption implementations use approved algorithms and properly validated cryptographic modules rather than custom or weak cryptography.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Approved cryptographic implementation

Implementation steps

  1. Document approved cryptographic standards specifying algorithms, key lengths, and modes of operation for each use case
  2. Implement FIPS-validated cryptographic modules for all encryption operations where required
  3. Disable weak or deprecated cryptographic algorithms and protocols across all systems and applications
  4. Conduct periodic cryptographic assessments to verify that all implementations comply with approved standards

Tools / systems

Evidence artifacts

Evidence frequency: Continuous enforcement; quarterly cryptographic compliance audit