Cryptographic Systems
With the expansion of the use of cryptographic systems an audit of encryption technology within a company is now critical. The use of SSL within web applications, key management, Virtual Private Networks, COMSEC procedures, the deployment of a corporate Public Key Infrastructure and actual cryptographic algorithms are audited.
For those companies that handle designated or classified Government of Canada information a Threat and Risk Assessment is required. A review of the cryptographic systems used to process designated or classified data is a mandatory part of a Threat and Risk Assessment.
