A policy for a policy
- Brian Couzens
- Jul 9
- 2 min read

ππ¨ π¨π«π ππ§π’π¬πππ’π¨π§π¬ π«πππ₯π₯π² π§πππ π π¬πππ§πππ₯π¨π§π ππ«π²π©ππ¨π π«ππ©π‘π² ππ¨π₯π’ππ²?
Iβm starting to think the default answer of βyesβ might be wrong.
I recently reviewed the Dutch Governmentβs Framework Cryptography Policy for the Central Government. Whatβs interesting is that it doesnβt push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across existing policies, standards, and controls.
That raises an uncomfortable question.
Are we solving a real problem⦠or creating a new layer of governance because cryptography feels important?
Most organisations already have:
- Information Security
- Risk Management
- Enterprise Architecture
- Procurement
- Secure Development
- Asset Management
- Identity & Access Management
- Business Continuity
- Third-Party Risk
- Operational Resilience
So where exactly does cryptography *not* fit?
When a dedicated policy makes sense
There are clear cases where cryptography is mission-critical:
- Government
- Defence
- Critical National Infrastructure
- Certificate Authorities
- Trust Service Providers
In these environments, cryptography isnβt just a control - itβs a core capability. A dedicated policy is justified.
But for everyone else?
This is where it gets harder to justify.
Do we really need a standalone cryptography policy - or are we creating a policy to coordinate other policies?
If:
- Asset Management governs cryptographic assets
- Procurement defines supplier requirements
- Architecture defines approved algorithms and patterns
- Risk manages cryptographic exposure
- Operations manages lifecycle and rotation
- Resilience covers recovery
β¦what gap is the cryptography policy actually filling?
Or is this how governance sprawl starts?
Because once we go down this path, where do we stop?
Policies for:
Databases. APIs. Networks. Identity. PKI. AI. Containers. Quantum.
At some point, the system collapses under its own weight.
The uncomfortable takeaway
Most organisations donβt have a cryptography policy problem.
They have a ππ«π²π©ππ¨π π«ππ©π‘π’π π π¨π―ππ«π§ππ§ππ π©π«π¨ππ₯ππ¦.
And governance is not a document.
Itβs accountability, decision-making, standards, architecture, risk, assurance, and continuous improvement.
A policy might support that.
But it doesnβt create it.
So Iβll ask the question directly:
Is a standalone cryptography policy genuinely necessary - or is it becoming another well-intentioned artefact that adds complexity without adding control?
Curious where people land on this.


Comments