Data in Use
What is Data in Use?
Data that is actively being processed, read, or modified in memory by a CPU or application. Protecting data in use is more challenging than data at rest or in transit and may involve techniques such as confidential computing.
Frameworks that govern data in use
What the standards actually require on data in use
Requirements naming data in use across 2 standards, quoted from the control text.
The confidentiality, integrity, and availability of data-in-use are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
NIST-CSF-PR.DS-10 · The confidentiality, integrity, and availability of data-in-use are protected →Apply Section 7 encryption and key management in cloud including: data at rest (provider-managed encryption + customer-managed encryption keys CMEK + Bring Your Own Key BYOK + Hold Your Own Key HYOK) + data in transit (TLS 1.3 + IPsec + mTLS) + data in use (co...
NISTSP144-4 · Encryption, Key Management, and BYOK →Questions people ask about data in use
What is Data in Use?
Why is Data in Use important for compliance?
Which compliance frameworks address Data in Use?
Where can I learn more about Data in Use?
See how Data in Use applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.