Talk With an Expert

Acceptable Encryption Standard

Acceptable Encryption Standard (PDF, 0.19MB)Acceptable Encryption Standard (DOCX, 0.15MB)Published: 15 Apr, 2025

Defining the minimum encryption requirements for securing sensitive data, ensuring that only cryptographic algorithms with substantial public review and proven effectiveness are utilized. The policy mandates adherence to recognized standards such as AES for symmetric encryption, RSA or Elliptic Curve Cryptography (ECC) for asymmetric encryption, and FIPS 140-2 compliance for cryptographic modules. Additionally, it specifies secure key management practices, authentication requirements, and guidelines for hash functions and key exchanges, ensuring compliance with industry regulations while safeguarding data from unauthorized access or compromise.