A policy for a policy
- Brian Couzens
- Jul 9
- 2 min read

𝐃𝐨 𝐨𝐫𝐠𝐚𝐧𝐢𝐬𝐚𝐭𝐢𝐨𝐧𝐬 𝐫𝐞𝐚𝐥𝐥𝐲 𝐧𝐞𝐞𝐝 𝐚 𝐬𝐭𝐚𝐧𝐝𝐚𝐥𝐨𝐧𝐞 𝐂𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐲 𝐏𝐨𝐥𝐢𝐜𝐲?
I’m starting to think the default answer of “yes” might be wrong.
I recently reviewed the Dutch Government’s Framework Cryptography Policy for the Central Government. What’s interesting is that it doesn’t push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across existing policies, standards, and controls.
That raises an uncomfortable question.
Are we solving a real problem… or creating a new layer of governance because cryptography feels important?
Most organisations already have:
- Information Security
- Risk Management
- Enterprise Architecture
- Procurement
- Secure Development
- Asset Management
- Identity & Access Management
- Business Continuity
- Third-Party Risk
- Operational Resilience
So where exactly does cryptography *not* fit?
When a dedicated policy makes sense
There are clear cases where cryptography is mission-critical:
- Government
- Defence
- Critical National Infrastructure
- Certificate Authorities
- Trust Service Providers
In these environments, cryptography isn’t just a control - it’s a core capability. A dedicated policy is justified.
But for everyone else?
This is where it gets harder to justify.
Do we really need a standalone cryptography policy - or are we creating a policy to coordinate other policies?
If:
- Asset Management governs cryptographic assets
- Procurement defines supplier requirements
- Architecture defines approved algorithms and patterns
- Risk manages cryptographic exposure
- Operations manages lifecycle and rotation
- Resilience covers recovery
…what gap is the cryptography policy actually filling?
Or is this how governance sprawl starts?
Because once we go down this path, where do we stop?
Policies for:
Databases. APIs. Networks. Identity. PKI. AI. Containers. Quantum.
At some point, the system collapses under its own weight.
The uncomfortable takeaway
Most organisations don’t have a cryptography policy problem.
They have a 𝐜𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐢𝐜 𝐠𝐨𝐯𝐞𝐫𝐧𝐚𝐧𝐜𝐞 𝐩𝐫𝐨𝐛𝐥𝐞𝐦.
And governance is not a document.
It’s accountability, decision-making, standards, architecture, risk, assurance, and continuous improvement.
A policy might support that.
But it doesn’t create it.
So I’ll ask the question directly:
Is a standalone cryptography policy genuinely necessary - or is it becoming another well-intentioned artefact that adds complexity without adding control?
Curious where people land on this.



Comments