πΌ SC-28 Protection of Information at Rest (L)(M)(H)
- Contextual name: πΌ SC-28 Protection of Information at Rest (L)(M)(H)
- ID:
/frameworks/fedramp-moderate-security-controls/sc/28
- Located in: πΌ System and Communications Protection
Descriptionβ
Protect the [FedRAMP Assignment: confidentiality AND integrity] of the following information at rest: [Assignment: organization-defined information at rest].
SC-28 Additional FedRAMP Requirements and Guidance:
Guidance: The organization supports the capability to use cryptographic mechanisms to protect information at rest.
Guidance: When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured.
Guidance: Note that this enhancement requires the use of cryptography in accordance with SC-13.
Similarβ
- Sections
/frameworks/fedramp-high-security-controls/sc/28
- Internal
- ID:
dec-c-ae145ea2
- ID:
Similar Sections (Take Policies From)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP High Security Controls β πΌ SC-28 Protection of Information at Rest (L)(M)(H) | 1 | 7 | 17 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ SC-28(1) Cryptographic Protection (L)(M)(H) | 12 |