πΌ SC-28 Protection of Information at Rest (L)(M)(H)
- Contextual name: πΌ SC-28 Protection of Information at Rest (L)(M)(H)
- ID:
/frameworks/fedramp-high-security-controls/sc/28
- Located in: πΌ System and Communications Protection
Descriptionβ
Protect the [FedRAMP Assignment: confidentiality AND integrity] of the following information at rest: [Assignment: organization-defined information at rest].
SC-28 Additional FedRAMP Requirements and Guidance:
Guidance: The organization supports the capability to use cryptographic mechanisms to protect information at rest.
Guidance: When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured.
Guidance: Note that this enhancement requires the use of cryptography in accordance with SC-13.
Similarβ
- Sections
/frameworks/nist-sp-800-53-r5/sc/28
- Internal
- ID:
dec-c-ae145ea2
- ID:
Similar Sections (Take Policies From)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST SP 800-53 Revision 5 β πΌ SC-28 Protection of Information at Rest | 3 | 15 | 18 |
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP Low Security Controls β πΌ SC-28 Protection of Information at Rest (L)(M)(H) | 1 | 17 | ||
πΌ FedRAMP Moderate Security Controls β πΌ SC-28 Protection of Information at Rest (L)(M)(H) | 1 | 17 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ SC-28(1) Cryptographic Protection (L)(M)(H) | 5 | 12 |
Policies (15)β
Internal Rulesβ
Rule | Policies | Flags |
---|---|---|
βοΈ dec-x-0bdcd276 | 1 | |
βοΈ dec-x-5c3c2067 | 1 | |
βοΈ dec-x-6ba5ecd2 | 1 | |
βοΈ dec-x-9cdb7407 | 1 | |
βοΈ dec-x-966d3183 | 1 | |
βοΈ dec-x-aef11ebd | 1 | |
βοΈ dec-x-f63fd4f0 | 1 |