Encryption at Rest
What is Encryption at Rest?
The encryption of data while it is stored on disk, database, or other storage media to protect it from unauthorized access if the storage is compromised.
Terms that appear alongside encryption at rest
Each of these is named in at least one of the same controls as encryption at rest. The number is how many controls name both.
- encryption 35 shared controls
- audit 18 shared controls
- nist 13 shared controls
- key management 13 shared controls
- breach notification 13 shared controls
- access control 12 shared controls
- integrity 11 shared controls
- pseudonymisation 10 shared controls
Frameworks that govern encryption at rest
What the standards actually require on encryption at rest
Requirements naming encryption at rest across 6 standards, quoted from the control text.
Ensure all data stores encrypt data at rest using KMS keys, enforce by default through account settings, SCPs and Config rules.
SEC08-BP02 · Enforce encryption at rest →ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) St...
ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS · ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM →ePHI encryption at rest and in transit. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.
ISO27799-02 · ePHI encryption at rest and in transit →Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities.
X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection · ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication + Anti-Tap + Anti-Eavesdrop + Post-Quantum Cryptography →Privacy (Puraibasii プライバシー) is the fourth of 10 Principles per Japan AI Guidelines for Business + intersects with APPI Act on Protection of Personal Information (2022 Amendment effective April 2023) + Copyright Act 2018 Amendment Article 30-4 (text and data mi...
JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection · Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle →HBNR compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL or CHIEF PRIVACY OFFICER - HBNR + state-law + HIPAA + GDPR + multi-regime coordination;
HBNR-Implementation-Roadmap-Org · HBNR Compliance Program Implementation - Organizational Roles, Detection, Incident Response, Records →Questions people ask about encryption at rest
What is Encryption at Rest?
Why is Encryption at Rest important for compliance?
Which compliance frameworks address Encryption at Rest?
Where can I learn more about Encryption at Rest?
See how Encryption at Rest applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.