unified
UC-CRYPTO-01 — Encrypt data at rest and in transit
Sensitive and nonpublic data at rest is rendered unreadable using strong, industry-accepted encryption, or truncation/tokenization for stored account data, with storage and retention minimized to defined business need. Data in transit is protected with strong cryptography and trusted certificates over all open, public, or external networks, rejecting fallback to insecure protocols. Transmission, movement, and removal of information, including to removable media, is restricted to authorized users and processes, and the integrity of data in both states is protected. Where encryption of nonpublic information is infeasible, compensating controls are documented, approved by the CISO, and reviewed at least annually.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Cryptography & Key Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CRYPTO-01
- title
- Encrypt data at rest and in transit
- statement
- Sensitive and nonpublic data at rest is rendered unreadable using strong, industry-accepted encryption, or truncation/tokenization for stored account data, with storage and retention minimized to defined business need. Data in transit is protected with strong cryptography and trusted certificates over all open, public, or external networks, rejecting fallback to insecure protocols. Transmission, movement, and removal of information, including to removable media, is restricted to authorized users and processes, and the integrity of data in both states is protected. Where encryption of nonpublic information is infeasible, compensating controls are documented, approved by the CISO, and reviewed at least annually.
- domain
- Cryptography & Key Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SC-8
- coverage
- partial
- delta
- confidentiality of internal-network transmission - the statement scopes transit encryption to open/public/external networks, while SC-8 applies to internal paths as well
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- SC-28
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- PR.DS-01
- coverage
- partial
- delta
- availability of data-at-rest (backup/redundancy), addressed by the backup control
- relationship
- intersects_with
- framework
- nist-csf-2
- control_id
- PR.DS-02
- coverage
- partial
- delta
- availability of data-in-transit (resilient/redundant communication paths) and confidentiality of transmission over internal network paths not addressed
- relationship
- intersects_with
- framework
- soc2
- control_id
- CC6.7
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.15
- coverage
- full
- relationship
- superset_of
- framework
- pci-dss
- control_id
- PCI-Req3
- coverage
- partial
- delta
- key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope
- relationship
- intersects_with
- framework
- pci-dss
- control_id
- PCI-Req4
- coverage
- full
- relationship
- superset_of
- framework
- hipaa
- control_id
- HIPAA-164.312(e)
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- E005
- coverage
- partial
- delta
- a documented storage-security description for AI data stores (training data, prompts, outputs, embeddings) shared with customers
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to PCI-Req3 — Protect stored account data
- framework
- pci-dss
- control_id
- PCI-Req3
- coverage
- partial
- delta
- key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-01 — Encrypt data at rest and in transit mitigates Compromised or counterfeit certificates / certificate authority
- strength
- related
- rationale
- Requires trusted certificates and rejects insecure fallback, helping reject rogue certs in MITM; the operative approved-CA/revocation defense sits in UC-CRYPTO-03.
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to PR.DS-01 — Data Security: The confidentiality, integrity, and availability of data-at-rest are protected
- framework
- nist-csf-2
- control_id
- PR.DS-01
- coverage
- partial
- delta
- availability of data-at-rest (backup/redundancy), addressed by the backup control
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Data Encryption & In-Use Protection Operations operates UC-CRYPTO-01 — Encrypt data at rest and in transit
- Security Control Assessment & POA&M Remediation tests UC-CRYPTO-01 — Encrypt data at rest and in transit
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to SC-8 — Transmission Confidentiality and Integrity
- framework
- nist-800-53
- control_id
- SC-8
- coverage
- partial
- delta
- confidentiality of internal-network transmission - the statement scopes transit encryption to open/public/external networks, while SC-8 applies to internal paths as well
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to HIPAA-164.312(e) — Transmission security for ePHI (integrity controls and encryption in transit)
- framework
- hipaa
- control_id
- HIPAA-164.312(e)
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-CRYPTO-01 — Encrypt data at rest and in transit
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to PCI-Req4 — Protect cardholder data with strong cryptography during transmission over open, public networks
- framework
- pci-dss
- control_id
- PCI-Req4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-01 — Encrypt data at rest and in transit mitigates Weak or absent encryption and key management
- strength
- primary
- rationale
- Renders data at rest unreadable and encrypts data in transit with strong cryptography, directly closing the absent/inadequate-encryption exposure for stored and transmitted data.
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to SC-28 — Protection of Information at Rest
- framework
- nist-800-53
- control_id
- SC-28
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-01 — Encrypt data at rest and in transit mitigates Credentials and sensitive data transmitted in clear text
- strength
- primary
- rationale
- Mandates strong encryption of data in transit over all public/external networks and rejects fallback to insecure protocols, directly preventing credentials and sensitive comms from crossing the wire in clear text.
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to 500.15 — Encryption of nonpublic information
- framework
- nydfs-500
- control_id
- 500.15
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to CC6.7 — The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives.
- framework
- soc2
- control_id
- CC6.7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Type II Interim Testing tests UC-CRYPTO-01 — Encrypt data at rest and in transit
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to PR.DS-02 — Data Security: The confidentiality, integrity, and availability of data-in-transit are protected
- framework
- nist-csf-2
- control_id
- PR.DS-02
- coverage
- partial
- delta
- availability of data-in-transit (resilient/redundant communication paths) and confidentiality of transmission over internal network paths not addressed
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CRYPTO-01 — Encrypt data at rest and in transit mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- primary
- rationale
- Strong in-transit encryption defeats passive sniffing/eavesdropping while trusted certificates and no-insecure-fallback block man-in-the-middle on public networks.
- UC-CRYPTO-01 — Encrypt data at rest and in transit maps_to E005 — Document data storage security
- framework
- aiuc-1
- control_id
- E005
- coverage
- partial
- delta
- a documented storage-security description for AI data stores (training data, prompts, outputs, embeddings) shared with customers
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.