← Knowledge areas
Knowledge area 03 · Govern

Cryptography
Governance

Turn cryptographic risk into accountable decisions, enforceable expectations and managed change.

Governance connects technical standards with risk appetite, ownership, exceptions, lifecycle decisions and evidence so cryptographic risk can be managed consistently across the organisation.

Last reviewed: August 2026

Strong algorithms do not create strong governance.

Modern cryptography can still be poorly governed when ownership is unclear, standards are inconsistent, exceptions persist indefinitely or teams cannot respond when requirements change.

Governance establishes what is permitted, who is accountable, how deviations are assessed, how transition is prioritised and what evidence leadership needs to understand material exposure.

Risk lens

Governance does not mean centralising every technical choice. It means knowing which decisions require control, who can make them, what evidence supports them and when they must be revisited.

Connect direction, standards, accountability and change.

01

Policy & principles

Define scope, mandatory outcomes, risk expectations and accountability.

02

Standards & baselines

Maintain approved and restricted algorithms, protocols, key strengths, certificate and key-management requirements.

03

Roles & decision rights

Clarify responsibilities across security, architecture, engineering, PKI, IAM, risk, procurement, suppliers and business owners.

04

Risk & exceptions

Require rationale, compensating controls, accountable acceptance, remediation and expiry for deviations.

05

Lifecycle oversight

Govern cryptography from design and procurement through operation, transition and retirement.

06

Assurance & reporting

Use evidence and risk reporting to determine whether expectations are operating effectively.

Separate durable direction from fast-changing implementation detail.

StrategicCryptography Policy

Scope, principles, accountability and mandatory organisational outcomes.

ControlCryptographic Standards

Approved or prohibited algorithms, protocols, strengths and lifecycle requirements.

OperationalProcedures & Patterns

How teams implement requirements in specific technologies and processes.

DecisionExceptions & Risk Acceptance

How temporary deviations are assessed, approved, monitored and remediated.

Policy statements connect to evidence and decisions.

Current policy & standardsApproved requirements with ownership and review cycles.
Inventory coverageEvidence that material cryptographic dependencies are identified and maintained.
Standards compliance viewKnown use of approved, transitional, deprecated or prohibited cryptography.
Exception registerRisk owners, expiry dates, compensating controls and remediation status.
Transition portfolioPrioritised remediation for deprecation, platform change and PQC migration.
Management insightReporting that shows exposure, blockers, concentration and decisions requiring escalation.

Exception principle

An exception is a time-bounded risk decision with an owner and treatment path — not a permanent workaround.

Build governance around the decisions that matter.

Assign accountable ownershipSeparate policy ownership, technical authority, service ownership and residual-risk acceptance.
Layer requirementsKeep high-level policy stable while standards and implementation patterns can evolve.
Make exceptions visibleRequire expiry, remediation and escalation for material deviations.
Measure exposurePrioritise coverage, standards exposure, overdue exceptions and migration blockers over activity counts.
Govern future changeUse architecture, procurement and supplier requirements to reduce the cost of the next transition.

Governance turns cryptographic change into a managed capability.

Algorithms and standards will continue to change. Crypto-agility provides the ability to change; governance provides the authority, priorities and evidence that make change consistent.

Together they turn migration from an emergency project into a repeatable organisational capability.

Further reading

Educational synthesis. Governance should be adapted to legal, regulatory, risk and technology context.

Previous knowledge area← Dependency MappingNext knowledge areaCrypto-Agility →