Skip to content

Encryption and key management plan

Planning aid, not a certification or legally sufficient compliance document. Complete in an approved private documentation location. Never insert credentials, key material, or actual restricted records. Unknown required controls block approval.

  • Project / nonsensitive identifier: [fill in]
  • Prepared by / accountable owner: [fill in]
  • Version / date / next review: [fill in]
  • Classification and agreement references: [fill in]
  • Approved evidence location: [fill in]

Encryption coverage

Layer / data copy Algorithm / format / version Who holds keys Configured scope Test / evidence Gap
Transfer / control and data channels
Data Store files and backend
VM scratch / swap
Replicas / snapshots / backups
Restricted outputs

Key lifecycle (identifiers only)

  • Generator and approved cryptographic/module requirements: [fill in]
  • Key id, custodian, vault/service and separation from data: [fill in]
  • Authorized release and runtime exposure: [fill in]
  • Nonce/IV requirements and authenticated format: [fill in]
  • Integrity, sender authenticity, and rollback protection: [fill in]
  • Cryptoperiod, rotation trigger, and old-copy re-encryption: [fill in]
  • Recovery custodian, escrow authorization, and recovery test: [fill in]
  • Compromise response, revocation and copied-key risks: [fill in]
  • Final destruction, retained key copies, and evidence: [fill in]
  • GoCommands mode limitations if used: [fill in]

Review and authorization

  • Unresolved controls / remediation owner / due date: [fill in]
  • Exceptions, approving authority, scope, and expiry: [fill in]
  • Custodian decision / date / evidence reference: [fill in]
  • Institutional decision / date / evidence reference: [fill in]
  • Provider confirmation references: [fill in]
  • Material changes requiring revalidation: [fill in]

For each control, record Supported, Configured, Verified, and Approved separately, with dates and evidence. Do not mark unknown as passed.