Encryption
What is Encryption?
The process of converting data into a coded format to prevent unauthorised access. Includes encryption at rest (stored data) and encryption in transit (data being transmitted).
Related terms
Frameworks that govern encryption
What the standards actually require on encryption
Requirements naming encryption across 6 standards, quoted from the control text.
When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.
ISM-1769 · When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256. →Encrypt storage on managed endpoint devices so data on a lost or stolen device is not disclosed.
CCM-UEM-08 · Storage Encryption →Encrypt cloud customer data while it is stored and keep the private keys known only to the customer, handling any exception through a specified procedure that is contractually agreed with that customer.
C5-CRY-03 · Encryption of sensitive data for storage →Sensitive data is encrypted in transit using current TLS versions with strong cipher suites and certificate validation.
IS-IV.F.2 · Data in Transit Encryption →Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities.
X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection · ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication + Anti-Tap + Anti-Eavesdrop + Post-Quantum Cryptography →Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or...
JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience · Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security →Questions people ask about encryption
What is Encryption?
Why is Encryption important for compliance?
What concepts are related to Encryption?
Which compliance frameworks address Encryption?
Where can I learn more about Encryption?
See how Encryption applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.