Cryptography
Cryptography is the practice of protecting information by transforming it so that only intended parties can read or verify it. It uses mathematical techniques and algorithms to keep data secure both when it is being transmitted and when it is stored. In practice, it helps prevent unauthorized access to sensitive information and supports secure communication.
Cryptography is the science and practice of information hiding and verification, encompassing the protocols, algorithms, and methodologies used to secure communication and protect data at rest and in transit against adversarial behavior. Drawing on mathematics and computer science, it applies encryption and related mathematical techniques to prevent unauthorized access, preserve confidentiality and integrity, and enable authentication. Within compliance contexts, cryptographic measures are typically implemented as one of several technical controls; specific requirements and their evaluation depend on the applicable criteria, scope, and framework (for example, the relevant Trust Services Criteria under a SOC 2 examination or the applicable Annex A reference controls selected via an ISO/IEC 27001 Statement of Applicability), and the presence of cryptographic controls does not by itself guarantee against compromise.
Why it matters
Cryptography is one of the foundational technical controls for protecting the confidentiality and integrity of information, whether that information is moving across a network or sitting in storage. Because it uses mathematical techniques to render data unreadable to unintended parties, it is a primary means of preventing unauthorized access to sensitive information and of supporting secure communication in the presence of adversarial behavior. For organizations undergoing a SOC 2 examination or pursuing ISO/IEC 27001 certification, cryptographic measures are frequently among the controls that auditors and certification bodies expect to see evaluated, though the specific expectations depend on scope and the applicable criteria.
In a SOC 2 context, cryptographic controls are typically assessed as part of the Common Criteria (Security) and, where relevant to scope, categories such as Confidentiality. Under ISO/IEC 27001, cryptography appears among the Annex A reference controls, which are selected through the Statement of Applicability and informed by the organization's risk assessment rather than applied uniformly. In both frameworks, the depth and manner of evaluation vary by auditor, certification body, and the defined scope of the engagement, so the way a given cryptographic control is scoped and tested is not fixed across engagements.
It is important to recognize the limits of what cryptography provides. The presence of cryptographic controls does not by itself guarantee against compromise; keys can be mishandled, algorithms can be misconfigured or become outdated, and controls that exist on paper may not operate effectively in practice. This is why a SOC 2 Type II examination assesses operating effectiveness over a defined period rather than mere design, and why ISO/IEC 27001 ties control selection to ongoing risk assessment. A SOC 2 report attests only to the controls and period covered, and an ISO/IEC 27001 certificate covers only the defined ISMS scope, so neither should be read as an assurance that encrypted data can never be breached.
Who it's relevant to
Inside Cryptography
Common questions
Answers to the questions practitioners most commonly ask about Cryptography.