Cryptographic Risk Assessment Form
Use this form to evaluate cryptographic security risks within your system or organization. Please answer all questions as accurately as possible.
System or Organization Name
*
Your Role or Position
*
Which cryptographic algorithms are currently in use?
*
AES
RSA
ECC
SHA-2/SHA-3
Other
How frequently are cryptographic keys rotated?
*
Monthly or more often
Quarterly
Annually
Rarely/Never
Rate the effectiveness of your organization's key management practices.
*
1
2
3
4
5
Is there a documented cryptography policy?
*
Yes, up to date
Yes, but outdated
No documented policy
Who has access to cryptographic keys?
*
Administrators only
Select technical staff
All IT staff
Other
When was your last cryptographic audit or assessment?
*
Please Select
Within the past year
1-2 years ago
More than 2 years ago
Never
Please rate your organization's overall cryptographic risk level.
*
Very Low
1
2
3
4
Very High
5
1 is Very Low, 5 is Very High
Cryptographic Risk Controls Matrix
*
Rows
Not Implemented
Partially Implemented
Fully Implemented
Data at Rest Encryption
1
2
3
Data in Transit Encryption
4
5
6
Key Management Procedures
7
8
9
Access Control to Keys
10
11
12
Additional Comments or Observations
Submit Assessment
Should be Empty: