Data at Rest Encryption
What is Data at Rest Encryption?
The protection of stored data using encryption algorithms so that the data remains unreadable without the proper decryption key, even if storage media is compromised.
Frameworks that govern data at rest encryption
What the standards actually require on data at rest encryption
Requirements naming data at rest encryption across 4 standards, quoted from the control text.
Encrypt data at rest using platform-managed or customer-managed keys for all storage services with documented key management.
DP-4 · Enable data at rest encryption by default →Sensitive data at rest is encrypted across databases, file systems, backups, and removable media using approved algorithms.
IS-IV.F.3 · Data at Rest Encryption →Encryption of data at rest. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.
ISO27043-17 · Encryption of data at rest →Encryption of data at rest. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.
ISO21434-17 · Encryption of data at rest →Questions people ask about data at rest encryption
What is Data at Rest Encryption?
Why is Data at Rest Encryption important for compliance?
Which compliance frameworks address Data at Rest Encryption?
Where can I learn more about Data at Rest Encryption?
See how Data at Rest Encryption applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.