PR.DS-1.1: The organization shall protect its critical system information determined to be critical/ sensitive while at rest.
Consider using encryption techniques for data storage, data transmission or data transport (e.g., laptop, USB).
Consider encrypting end-user devices and removable media containing sensitive data (e.g. hard disks, laptops, mobile device, USB storage devices, …). This could be done by e.g. Windows BitLocker®, VeraCrypt, Apple FileVault®, Linux® dm-crypt,…
Consider encrypting sensitive data stored in the cloud.
Implement dedicated safeguards to prevent unauthorized access, distortion, or modification of system data and audit records (e.g. restricted access rights, daily backups, data encryption, firewall installation).
Encrypt hard drives, external media, stored files, configuration files and data stored in the cloud.
Documentation Maturity
Implementation Maturity
Description
The organization shall protect its critical system information determined to be critical/ sensitive while at rest.