Skip to content
English
  • There are no suggestions because the search field is empty.

Secure Management of Encryption Mechanisms and Cryptographic Keys at Eye-Able

How does Eye-Able ensure that encryption mechanisms and cryptographic keys are managed securely?

This article gives an overview of Eye-Able's cryptography and key management programme, including policies, key rotation, deletion, auditability and regulatory compliance.


Cryptography and key management programme

Eye-Able operates a formalised cryptography and key management programme that is aligned with current industry standards (e.g. ISO/IEC 19790, NIST, BSI TR-02102) and regulatory requirements.


Cryptographic procedures and data classification

All cryptographic procedures – both for data at rest and data in transit – use certified libraries and are applied on the basis of an approved data classification.


Key management and rights management

Keys are generated exclusively through controlled processes, rotate in accordance with defined crypto periods and are subject to a tiered rights management scheme based on the least privilege principle.


Access controls and process rules

Access to key material is technically restricted; all key transitions, archiving, deactivation and deletion are governed by documented processes.


Exception procedures and logging

Exception procedures (e.g. special use of compromised keys for decryption purposes) are procedurally safeguarded and auditable.

All key status changes are logged, monitored in central systems and audited regularly – particularly after security-relevant events.


Key retirement and legally compliant processes

Key retirement and key destruction processes are designed to be legally compliant and include HSM-based keys.


Changes to cryptographic standards

Changes to cryptographic standards, algorithms or procedures are assessed in a risk-based manner, documented and introduced in a controlled way.


Integration into the ISMS

Key management is embedded in the overarching ISMS and meets the requirements for data confidentiality, integrity and traceability at both the technical and organisational level.


Further help

Do you have further questions or need personal support? The following article explains how you can get in touch with us: