Protection of Information at Rest
LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Protect the [one of: confidentiality; integrity] of the following information at rest: [information at rest].
Discussion (NIST Supplemental Guidance)
Information at rest refers to the state of information when it is not in process or in transit and is located on system components. Such components include internal or external hard disk drives, storage area network devices, or databases. However, the focus of protecting information at rest is not on the type of storage device or frequency of access but rather on the state of the information. Information at rest addresses the confidentiality and integrity of information and covers user information and system information. System-related information that requires protection includes configurations or rule sets for firewalls, intrusion detection and prevention systems, filtering routers, and authentication information. Organizations may employ different mechanisms to achieve confidentiality and integrity protections, including the use of cryptographic mechanisms and file share scanning. Integrity protection can be achieved, for example, by implementing write-once-read-many (WORM) technologies. When adequate protection of information at rest cannot otherwise be achieved, organizations may employ other controls, including frequent scanning to identify malicious code at rest and secure offline storage in lieu of online storage.
Enhancements NIST SOURCE
SC-28(1) Cryptographic Protection LOW ✓ MODERATE ✓ HIGH
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on [system components or media]: [information].
Discussion
The selection of cryptographic mechanisms is based on the need to protect the confidentiality and integrity of organizational information. The strength of mechanism is commensurate with the security category or classification of the information. Organizations have the flexibility to encrypt information on system components or media or encrypt data structures, including files, records, or fields.
SC-28(2) Offline Storage LOW MODERATE HIGH
Remove the following information from online storage and store offline in a secure location: [information].
Discussion
Removing organizational information from online storage to offline storage eliminates the possibility of individuals gaining unauthorized access to the information through a network. Therefore, organizations may choose to move information to offline storage in lieu of protecting such information in online storage.
SC-28(3) Cryptographic Keys LOW MODERATE HIGH
Provide protected storage for cryptographic keys [one of: ; hardware-protected key store].
Discussion
A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-28 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- one or more of the following PARAMETER VALUES is/are selected: {confidentiality; integrity};
- information at rest requiring protection is defined;
- the <SC-28_ODP[01] SELECTED PARAMETER VALUES> of <SC-28_ODP[02] information at rest> is/are protected.
Examine
[SELECT FROM: System and communications protection policy; procedures addressing the protection of information at rest; system design documentation; system configuration settings and associated documentation; cryptographic mechanisms and associated configuration documentation; list of information at rest requiring confidentiality and integrity protections; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; system developer].
Test
[SELECT FROM: Mechanisms supporting and/or implementing confidentiality and integrity protections for information at rest].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-28. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- system security plan
Configuration
- system design documentation
- system configuration settings and associated documentation
- cryptographic mechanisms and associated configuration documentation
Testing
- Mechanisms supporting and/or implementing confidentiality and integrity protections for information at rest
Other Records
- procedures addressing the protection of information at rest
- list of information at rest requiring confidentiality and integrity protections
- other relevant documents or records