EKM-03: Sensitive Data Protection
Control Family:
Threats Addressed:
Control is withdrawn in the next version of this control set and incorporated into: CEK-01: Encryption and Key Management Policy and Procedures, CEK-03: Data Encryption, DSP-10: Sensitive Data Transfer, LOG-10: Encryption Monitoring and Reporting.
Control Statement
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for the use of encryption protocols for protection of sensitive data in storage (e.g., file servers, databases, and end-user workstations), data in use (memory), and data in transmission (e.g., system interfaces, over public networks, and electronic messaging) as per applicable legal, statutory, and regulatory compliance obligations.
[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]
Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.