<p>This article addresses the problem of auditing encryption and key management security policies in web-server systems based on system analysis and formal modeling. The relevance of the study stems from the fact that the mere presence of cryptographic protection mechanisms does not guarantee their correct and complete implementation in accordance with policy requirements, which may result in discrepancies between actual system configurations and regulatory requirements. The aim of the study is to formalize policy requirements and audit evidence within a unified framework, develop a mechanism for their matching, and propose an assessment model based on indicators of compliance, audit completeness, risk, consistency, stability, and adaptability. The study employs system analysis, formal specification, indicator-based evaluation, logical relationship modeling, and algorithm design methods. As a result, a multilayer audit object model, an approach for matching policy requirements with audit evidence, an assessment mechanism accounting for partial compliance, and a risk-oriented integrated audit model were developed. The proposed approach can be applied to the assessment of web-server infrastructures, application software systems, and key management processes, as well as to the prioritization of audit findings and the support of managerial decision-making. In conclusion, the developed model transforms cryptographic policy auditing from a set of isolated checks into a <br /> coherent, measurable, and algorithmically processable scientific framework.</p>