Skip to content

Data at Rest

What is Data at Rest?

Data that is stored in any digital form on persistent storage media such as hard drives, SSDs, databases, or cloud storage. Encryption of data at rest is a common security requirement across compliance frameworks.

Information Security

Each of these is named in at least one of the same controls as data at rest. The number is how many controls name both.

What the standards actually require on data at rest

Requirements naming data at rest across 6 standards, quoted from the control text.

Use automated controls such as Config remediation, EventBridge actions and SCPs to detect and correct unencrypted or improperly protected data automatically.

SEC08-BP03 · Automate data at rest protection

Encrypt data at rest using platform-managed or customer-managed keys for all storage services with documented key management.

DP-4 · Enable data at rest encryption by default

Encrypt sensitive data at rest on servers, applications, and databases. Storage-layer encryption is recommended.

3.11 · Encrypt Sensitive Data at Rest

Apply encryption for stored data and data in transit based on a risk assessment of the assets in question.

ASIC-CR-PR-3 · Encryption of data at rest and in transit

Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard.

CIS-3.11 · Encrypt Sensitive Data at Rest

Sensitive data at rest is encrypted across databases, file systems, backups, and removable media using approved algorithms.

IS-IV.F.3 · Data at Rest Encryption

Questions people ask about data at rest

What is Data at Rest?
Data that is stored in any digital form on persistent storage media such as hard drives, SSDs, databases, or cloud storage. Encryption of data at rest is a common security requirement across compliance frameworks.
Why is Data at Rest important for compliance?
Data at Rest is a key concept in Information Security. Understanding data at rest helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data at Rest?
Data at Rest appears in the requirement text of AWS Well-Architected Security Pillar, Azure Security Benchmark, NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements, ASIC Cyber Resilience Good Practices, CIS Controls v8. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data at Rest?
Explore our compliance framework pages to see how data at rest applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data at Rest applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.