unified

UC-CRYPTO-01 — Encrypt data at rest and in transit

Sensitive and nonpublic data at rest is rendered unreadable using strong, industry-accepted encryption, or truncation/tokenization for stored account data, with storage and retention minimized to defined business need. Data in transit is protected with strong cryptography and trusted certificates over all open, public, or external networks, rejecting fallback to insecure protocols. Transmission, movement, and removal of information, including to removable media, is restricted to authorized users and processes, and the integrity of data in both states is protected. Where encryption of nonpublic information is infeasible, compensating controls are documented, approved by the CISO, and reviewed at least annually.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Cryptography & Key Management
type
preventive
category
technical

Details

unified_id
UC-CRYPTO-01
title
Encrypt data at rest and in transit
statement
Sensitive and nonpublic data at rest is rendered unreadable using strong, industry-accepted encryption, or truncation/tokenization for stored account data, with storage and retention minimized to defined business need. Data in transit is protected with strong cryptography and trusted certificates over all open, public, or external networks, rejecting fallback to insecure protocols. Transmission, movement, and removal of information, including to removable media, is restricted to authorized users and processes, and the integrity of data in both states is protected. Where encryption of nonpublic information is infeasible, compensating controls are documented, approved by the CISO, and reviewed at least annually.
domain
Cryptography & Key Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    SC-8
    coverage
    partial
    delta
    confidentiality of internal-network transmission - the statement scopes transit encryption to open/public/external networks, while SC-8 applies to internal paths as well
    relationship
    intersects_with
  • framework
    nist-800-53
    control_id
    SC-28
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    PR.DS-01
    coverage
    partial
    delta
    availability of data-at-rest (backup/redundancy), addressed by the backup control
    relationship
    intersects_with
  • framework
    nist-csf-2
    control_id
    PR.DS-02
    coverage
    partial
    delta
    availability of data-in-transit (resilient/redundant communication paths) and confidentiality of transmission over internal network paths not addressed
    relationship
    intersects_with
  • framework
    soc2
    control_id
    CC6.7
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.15
    coverage
    full
    relationship
    superset_of
  • framework
    pci-dss
    control_id
    PCI-Req3
    coverage
    partial
    delta
    key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope
    relationship
    intersects_with
  • framework
    pci-dss
    control_id
    PCI-Req4
    coverage
    full
    relationship
    superset_of
  • framework
    hipaa
    control_id
    HIPAA-164.312(e)
    coverage
    full
    relationship
    superset_of
  • framework
    aiuc-1
    control_id
    E005
    coverage
    partial
    delta
    a documented storage-security description for AI data stores (training data, prompts, outputs, embeddings) shared with customers
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections