{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Cryptography & Key Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-01","description":"Sensitive and nonpublic data at rest is rendered unreadable using strong, industry-accepted encryption, or truncation/tokenization for stored account data, with storage and retention minimized to defined business need. Data in transit is protected with strong cryptography and trusted certificates over all open, public, or external networks, rejecting fallback to insecure protocols. Transmission, movement, and removal of information, including to removable media, is restricted to authorized users and processes, and the integrity of data in both states is protected. Where encryption of nonpublic information is infeasible, compensating controls are documented, approved by the CISO, and reviewed at least annually.","details":{"control_category":"technical","control_type":"preventive","domain":"Cryptography & Key Management","guidance":[],"members":[{"control_id":"SC-8","coverage":"partial","delta":"confidentiality of internal-network transmission - the statement scopes transit encryption to open/public/external networks, while SC-8 applies to internal paths as well","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"SC-28","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.DS-01","coverage":"partial","delta":"availability of data-at-rest (backup/redundancy), addressed by the backup control","framework":"nist-csf-2","relationship":"intersects_with"},{"control_id":"PR.DS-02","coverage":"partial","delta":"availability of data-in-transit (resilient/redundant communication paths) and confidentiality of transmission over internal network paths not addressed","framework":"nist-csf-2","relationship":"intersects_with"},{"control_id":"CC6.7","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"500.15","coverage":"full","framework":"nydfs-500","relationship":"superset_of"},{"control_id":"PCI-Req3","coverage":"partial","delta":"key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope","framework":"pci-dss","relationship":"intersects_with"},{"control_id":"PCI-Req4","coverage":"full","framework":"pci-dss","relationship":"superset_of"},{"control_id":"HIPAA-164.312(e)","coverage":"full","framework":"hipaa","relationship":"superset_of"},{"control_id":"E005","coverage":"partial","delta":"a documented storage-security description for AI data stores (training data, prompts, outputs, embeddings) shared with customers","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"Sensitive and nonpublic data at rest is rendered unreadable using strong, industry-accepted encryption, or truncation/tokenization for stored account data, with storage and retention minimized to defined business need. Data in transit is protected with strong cryptography and trusted certificates over all open, public, or external networks, rejecting fallback to insecure protocols. Transmission, movement, and removal of information, including to removable media, is restricted to authorized users and processes, and the integrity of data in both states is protected. Where encryption of nonpublic information is infeasible, compensating controls are documented, approved by the CISO, and reviewed at least annually.","title":"Encrypt data at rest and in transit","unified_id":"UC-CRYPTO-01"},"id":"uc:UC-CRYPTO-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-01","sourceIds":["aiuc-1","hipaa","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"UC-CRYPTO-01 — Encrypt data at rest and in transit","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0dce2b553d8180d563cc2e7c6531b355e611e4d980a6a281d29355e9bca8080d","properties":{"control_id":"PCI-Req3","coverage":"partial","delta":"key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req3-e250c900.json","targetId":"ctrl:pci-dss:PCI-Req3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13f64e9bd86f0bc703948908c3cf78914b528e48bfb571ac0392522a46ce644f","properties":{"rationale":"Requires trusted certificates and rejects insecure fallback, helping reject rogue certs in MITM; the operative approved-CA/revocation defense sits in UC-CRYPTO-03.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-counterfeit-certificates-d9dcc5c5.json","targetId":"risk:crypto-counterfeit-certificates","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:223afce98b0c8b317705d72570f1bcd6cfc98864226f4103fa45a9ccb2d25d06","properties":{"control_id":"PR.DS-01","coverage":"partial","delta":"availability of data-at-rest (backup/redundancy), addressed by the backup control","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-01-e42f5cc9.json","targetId":"ctrl:nist-csf-2:PR.DS-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:382cfd77994c884aa61fa4aecb0954e212a241cf5c56f9622c28f315fbacd306","properties":{},"sourceDetailPath":"/data/v1/records/wf-c33-0d69c278.json","sourceId":"wf:C33","targetDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","targetId":"uc:UC-CRYPTO-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:472917974cf01e71f7c62132ab43af5d7008e9caa96cfd84844ed594537fdfbe","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","targetId":"uc:UC-CRYPTO-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f9cc2273c050ccc6e31960e18dc9c62d82130369aa71bdb6d12c9f12d6623e5","properties":{"control_id":"SC-8","coverage":"partial","delta":"confidentiality of internal-network transmission - the statement scopes transit encryption to open/public/external networks, while SC-8 applies to internal paths as well","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-8-56ac3e1a.json","targetId":"ctrl:nist-800-53:SC-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b2e1633576aec74797561acd8e2770e4a4b3bf329e76e821b581925d07ae4ea","properties":{"control_id":"HIPAA-164.312(e)","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-e-edf6e525.json","targetId":"ctrl:hipaa:HIPAA-164.312(e)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f03059d6bc5a5a4da403477646240470c751ea73a28d2e73dfccc3e483a15ea","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","targetId":"uc:UC-CRYPTO-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72f2f56ed842044eb3de32bf36817661690a614e723a5968076b33ae0a52bed4","properties":{"control_id":"PCI-Req4","coverage":"full","delta":null,"framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req4-e571f282.json","targetId":"ctrl:pci-dss:PCI-Req4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8970c33bddd154c3cef76c7c7d82e5a8d118c74e982d2ab08a338dc51797f3fa","properties":{"rationale":"Renders data at rest unreadable and encrypts data in transit with strong cryptography, directly closing the absent/inadequate-encryption exposure for stored and transmitted data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a397b05f1ef48f04a32884b2d7ea38857e1cdd261143b3ae301684d637fb170f","properties":{"control_id":"SC-28","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-28-740b8f3c.json","targetId":"ctrl:nist-800-53:SC-28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b312a3465956656f933a2d24079ffb3960496f2c22e14a96ad449d31cfe0d456","properties":{"rationale":"Mandates strong encryption of data in transit over all public/external networks and rejects fallback to insecure protocols, directly preventing credentials and sensitive comms from crossing the wire in clear text.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-cleartext-credential-transfer-b88065a1.json","targetId":"risk:crypto-cleartext-credential-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b710763db006c50e74e56979f08771abc6a21fb508e06abd61239f155d4f359f","properties":{"control_id":"500.15","coverage":"full","delta":null,"framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-15-5ef052ba.json","targetId":"ctrl:nydfs-500:500.15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6b7a150cb296f8a9ed43aae0b1ffa79c70c4d2bc56ea7ad7afe13fc2d1d0bb7","properties":{"control_id":"CC6.7","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-7-f815d553.json","targetId":"ctrl:soc2:CC6.7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d5c1888dca99c54c60043fbaf6c28732c9f8ce67cd84414d4b81dc741b6dfc38","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","targetId":"uc:UC-CRYPTO-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e0f381630542302cf8acba984eb66a245a46ea45dca2726c9b73a4a6bda93719","properties":{"control_id":"PR.DS-02","coverage":"partial","delta":"availability of data-in-transit (resilient/redundant communication paths) and confidentiality of transmission over internal network paths not addressed","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-02-3ef7fff1.json","targetId":"ctrl:nist-csf-2:PR.DS-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e4632b900396dc6c7410ef9ed56bae45ef8e045dfe089098dd265a1e59338d80","properties":{"rationale":"Strong in-transit encryption defeats passive sniffing/eavesdropping while trusted certificates and no-insecure-fallback block man-in-the-middle on public networks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f612cb7fa3626c23b14987a9f2c48cde12aeec66b78ff44a1a237710e62d4a28","properties":{"control_id":"E005","coverage":"partial","delta":"a documented storage-security description for AI data stores (training data, prompts, outputs, embeddings) shared with customers","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e005-8a88c16c.json","targetId":"ctrl:aiuc-1:E005","type":"maps_to"}],"schemaVersion":1}
