Skip to content

Encryption at Rest

What is Encryption at Rest?

The encryption of data while it is stored on disk, database, or other storage media to protect it from unauthorized access if the storage is compromised.

Privacy and Data Protection

Each of these is named in at least one of the same controls as encryption at rest. The number is how many controls name both.

What the standards actually require on encryption at rest

Requirements naming encryption at rest across 6 standards, quoted from the control text.

Ensure all data stores encrypt data at rest using KMS keys, enforce by default through account settings, SCPs and Config rules.

SEC08-BP02 · Enforce encryption at rest
ISMAP (Japan)1 control

ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) St...

ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS · ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM
ISO 277991 control

ePHI encryption at rest and in transit. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.

ISO27799-02 · ePHI encryption at rest and in transit

Privacy (Puraibasii プライバシー) is the fourth of 10 Principles per Japan AI Guidelines for Business + intersects with APPI Act on Protection of Personal Information (2022 Amendment effective April 2023) + Copyright Act 2018 Amendment Article 30-4 (text and data mi...

JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection · Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle

HBNR compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL or CHIEF PRIVACY OFFICER - HBNR + state-law + HIPAA + GDPR + multi-regime coordination;

HBNR-Implementation-Roadmap-Org · HBNR Compliance Program Implementation - Organizational Roles, Detection, Incident Response, Records

Questions people ask about encryption at rest

What is Encryption at Rest?
The encryption of data while it is stored on disk, database, or other storage media to protect it from unauthorized access if the storage is compromised.
Why is Encryption at Rest important for compliance?
Encryption at Rest is a key concept in Privacy and Data Protection. Understanding encryption at rest helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Encryption at Rest?
Encryption at Rest appears in the requirement text of AWS Well-Architected Security Pillar, ISMAP (Japan), ISO 27799, ITU-T X.805 - Security Architecture for End-to-End Communications, Japan AI Guidelines. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Encryption at Rest?
Explore our compliance framework pages to see how encryption at rest applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Encryption at Rest applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.