Disk Encryption
What is Disk Encryption?
The encryption of an entire disk or storage volume so that all data stored on it is automatically encrypted and requires authentication to access.
Terms that appear alongside disk encryption
Each of these is named in at least one of the same controls as disk encryption. The number is how many controls name both.
- encryption 4 shared controls
- hardening 2 shared controls
- cis benchmarks 2 shared controls
- secure boot 2 shared controls
- ssh 2 shared controls
- full disk encryption 2 shared controls
- data at rest 2 shared controls
Frameworks that govern disk encryption
What the standards actually require on disk encryption
Requirements naming disk encryption across 4 standards, quoted from the control text.
Full disk encryption, or partial encryption where access controls will only allow writing to the encrypted partition, is implemented when encrypting data at rest.
ISM-0459 · Full disk encryption, or partial encryption where access controls will only allow writing →Apply Section 5.3 cryptography including: encryption of data at rest (AES-256 + FIPS 140-3 validated modules + full disk encryption + file-level encryption + database encryption) + data in transit (TLS 1.3 + IPsec + SSH 2.0 + S/MIME + PGP) + key management per...
NISTSP123-4 · Server Cryptography - Encryption, Key Management, Certificates →Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities.
X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection · ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication + Anti-Tap + Anti-Eavesdrop + Post-Quantum Cryptography →Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load...
MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot · MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot →Questions people ask about disk encryption
What is Disk Encryption?
Why is Disk Encryption important for compliance?
Which compliance frameworks address Disk Encryption?
Where can I learn more about Disk Encryption?
See how Disk Encryption applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.