Skip to content

Data at Rest Encryption

What is Data at Rest Encryption?

The protection of stored data using encryption algorithms so that the data remains unreadable without the proper decryption key, even if storage media is compromised.

Information Security

What the standards actually require on data at rest encryption

Requirements naming data at rest encryption across 4 standards, quoted from the control text.

Encrypt data at rest using platform-managed or customer-managed keys for all storage services with documented key management.

DP-4 · Enable data at rest encryption by default

Sensitive data at rest is encrypted across databases, file systems, backups, and removable media using approved algorithms.

IS-IV.F.3 · Data at Rest Encryption
ISO 270431 control

Encryption of data at rest. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.

ISO27043-17 · Encryption of data at rest
ISO/SAE 214341 control

Encryption of data at rest. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.

ISO21434-17 · Encryption of data at rest

Questions people ask about data at rest encryption

What is Data at Rest Encryption?
The protection of stored data using encryption algorithms so that the data remains unreadable without the proper decryption key, even if storage media is compromised.
Why is Data at Rest Encryption important for compliance?
Data at Rest Encryption is a key concept in Information Security. Understanding data at rest encryption helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data at Rest Encryption?
Data at Rest Encryption appears in the requirement text of Azure Security Benchmark, FFIEC IT Examination Handbook, ISO 27043, ISO/SAE 21434. Across these standards we have identified 5 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data at Rest Encryption?
Explore our compliance framework pages to see how data at rest encryption applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data at Rest Encryption applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.