Skip to content

SC-28: Protection of Information at Rest

An OSCAL Control

Statement

    • Protect the of the following information at rest: .

        • Guidance:

          The organization supports the capability to use cryptographic mechanisms to protect information at rest.

        • Guidance:

          When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured.

        • Guidance:

          Note that this enhancement requires the use of cryptography in accordance with SC-13.