Key Management Policy | DefectDojo Trust Center

Key Management Policy

Purpose

The purpose of this policy is to ensure the proper lifecycle management of encryption keys to protect the confidentiality and integrity of confidential information. Additionally, it informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding the management of encryption keys across all systems, networks, IT assets, and licensed software owned, operated, or used by DefectDojo.

Scope

This policy applies to confidential and personal information processed, stored, or transmitted at DefectDojo.

Compliance

Compliance Measurement

The Information Security Management team will verify compliance to this document through various methods, including but not limited to business tool reports, internal and external audits, and feedback to the document owner.

Exceptions

Any exception to this document must be reviewed and approved in advance by the Management Review Team.

Non-Compliance

Any DefectDojo Staff found to have violated this document may be subject to disciplinary action, up to and including termination of employment.

Continual Improvement

This document is updated and reviewed as part of the continual improvement process.

Requirements

Principle

Cryptographic Key Management is based on OWASP guidelines - Key Management - OWASP Cheat Sheet Series. All cryptographic keys must be managed as confidential information.

Key Generation

Key Distribution

Key Storage

Key Operations

Key Rotation and Master Key Access

Key Sharing

Key Escrow and Backup

Trust Stores

Cryptographic Key Management Libraries

Relevant Documents