Crypto Approval Authority
Article 6
1. The Crypto Approval Authority shall be responsible for approving the use of encrypting technologies. 2. The Crypto Approval Authority shall issue guidance on the requirements for the use and approval of encrypting technologies. 3. The Crypto Approval Authority shall approve the use of encryption solutions on the basis of a request from the system owner. The approval shall be based upon a satisfactory evaluation of at least: (a) the security needs of the information to be protected; (b) an overview of the CIS involved in the solution; (c) an assessment of the inherent and residual risks; (d) a description of the proposed solution; (e) the SecOPs for the encryption solution. 4. The Crypto Approval Authority shall keep a register of approved encryption solutions.