Cryptography for IS Auditors
You don't need the maths. You need to know which key does what, and where key management fails.
Cryptography turns readable data into a form only the right key can unlock, and lets a recipient check who sent a message and whether it was changed. An IS auditor doesn't need the mathematics. You need to know which mechanism delivers which security goal, who holds which key, and how keys are managed, because that is where real systems fail.
For Indian practice it also has legal weight: the IT Act defines a digital signature in terms of an asymmetric crypto system and a hash function, and every DSC a CA uses for filings rests on that definition.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
Which Mechanism Gives Which Goal
Confidentiality (only the recipient can read)
Mechanism
Symmetric encryption, or asymmetric encryption of a session key
Key used
Shared secret key; or the recipient's public key to encrypt, recipient's private key to decrypt
Integrity (data unchanged)
Mechanism
Hash function, or a message authentication code
Key used
No key for a plain hash; shared key for a MAC
Authentication of the sender
Mechanism
Digital signature
Key used
Sender signs with own private key; anyone verifies with the sender's public key
Non-repudiation (sender can't deny)
Mechanism
Digital signature backed by a certificate from a trusted certifying authority
Key used
Sender's private key, which only the sender holds
| Goal | Mechanism | Key used |
|---|---|---|
| Confidentiality (only the recipient can read) | Symmetric encryption, or asymmetric encryption of a session key | Shared secret key; or the recipient's public key to encrypt, recipient's private key to decrypt |
| Integrity (data unchanged) | Hash function, or a message authentication code | No key for a plain hash; shared key for a MAC |
| Authentication of the sender | Digital signature | Sender signs with own private key; anyone verifies with the sender's public key |
| Non-repudiation (sender can't deny) | Digital signature backed by a certificate from a trusted certifying authority | Sender's private key, which only the sender holds |
Core Terms
- Symmetric encryption
- One shared key encrypts and decrypts. Fast, so used for bulk data. AES (NIST FIPS 197) is the standard: 128-bit blocks with 128, 192 or 256-bit keys. The hard part is sharing the key safely.
- Asymmetric (public key) encryption
- A mathematically linked key pair: a public key anyone can have and a private key only the owner holds. Slower, so mostly used to exchange symmetric keys and to sign.
- Hash function
- Turns any input into a short fixed-length value. The same input always gives the same hash, and it should be computationally infeasible to reverse it or to find two inputs with the same hash. The IT Act's own explanation in section 3 says the same.
- Digital signature
- The hash of a message, encrypted with the sender's private key. The recipient decrypts it with the sender's public key and compares hashes.
- PKI and certifying authorities
- Public key infrastructure binds a public key to a person through a certificate issued by a certifying authority. In India, certifying authorities are licensed under the IT Act, which provides for a Controller of Certifying Authorities.
- Key management
- Generating, distributing, storing, rotating, revoking and destroying keys. Most real crypto failures are key management failures, not broken algorithms.
Algorithm Status as of October 2026
NIST announced in December 2022 that SHA-1 is to be phased out by 31 December 2030 because collision attacks are now practical; SHA-2 and SHA-3 are the replacements. In August 2024 NIST approved its first post-quantum standards (FIPS 203 for key encapsulation, FIPS 204 and 205 for digital signatures), designed to resist attacks by future quantum computers. Course material written in 2020 predates both announcements, so it cannot reflect them.
Quick practice on audit concepts. No signup.
What the Auditor Checks
- checkA cryptography or key management policy that names approved algorithms and key lengths
- checkAn inventory of where encryption is used: data at rest (databases, laptops, backups) and in transit (web, VPN, interfaces to banks and the GST portal)
- checkKeys stored apart from the data they protect, ideally in a hardware security module or managed key service, with access logged
- checkKey rotation, revocation on compromise, and recovery procedures documented and tested
- checkCertificates tracked for expiry, so a lapsed certificate does not stop a payment interface
- checkRetired algorithms (such as SHA-1) identified and on a migration plan
How the DISA Assessment Test Tests This
Expect "which key" questions. A sender who wants confidentiality encrypts with the recipient's public key; a sender who wants to sign uses their own private key. The most common wrong answer swaps these.
The second trap: a digital signature alone does not give confidentiality. It proves origin and integrity, but the message itself can still be read unless it is also encrypted. Questions on hashing test the one-way property: a hash cannot be "decrypted".
FAQs
What is the difference between symmetric and asymmetric encryption?expand_more
Symmetric uses one shared key for both encryption and decryption and is fast. Asymmetric uses a public and private key pair, is slower, and solves the key-sharing problem.
Which key is used to create a digital signature?expand_more
The signer's private key. Anyone can verify the signature with the signer's public key.
Does a digital signature provide confidentiality?expand_more
No. It provides authentication, integrity and non-repudiation. For confidentiality the message must also be encrypted.
What does the IT Act say about digital signatures?expand_more
Section 3 lets a subscriber authenticate an electronic record with a digital signature, effected by an asymmetric crypto system and hash function, verifiable with the subscriber's public key. Section 3A adds other electronic signatures the Act recognises as reliable.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
