Skip to content

Encryption

What is Encryption?

The process of converting data into a coded format to prevent unauthorised access. Includes encryption at rest (stored data) and encryption in transit (data being transmitted).

Information Security

What the standards actually require on encryption

Requirements naming encryption across 6 standards, quoted from the control text.

When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.

ISM-1769 · When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.

Encrypt storage on managed endpoint devices so data on a lost or stolen device is not disclosed.

CCM-UEM-08 · Storage Encryption
C5 (Germany)7 controls

Encrypt cloud customer data while it is stored and keep the private keys known only to the customer, handling any exception through a specified procedure that is contractually agreed with that customer.

C5-CRY-03 · Encryption of sensitive data for storage

Sensitive data is encrypted in transit using current TLS versions with strong cipher suites and certificate validation.

IS-IV.F.2 · Data in Transit Encryption

Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or...

JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience · Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security

Questions people ask about encryption

What is Encryption?
The process of converting data into a coded format to prevent unauthorised access. Includes encryption at rest (stored data) and encryption in transit (data being transmitted).
Why is Encryption important for compliance?
Encryption is a key concept in Information Security. Understanding encryption helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Encryption?
Key concepts related to Encryption include Confidentiality. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Encryption?
Encryption appears in the requirement text of Australian Information Security Manual, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, C5 (Germany), FFIEC IT Examination Handbook, ITU-T X.805 - Security Architecture for End-to-End Communications. Across these standards we have identified 55 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Encryption?
Explore our compliance framework pages to see how encryption applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Encryption applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.