PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected
Threats Addressed:
Previous Version:
- NIST Cybersecurity Framework v1.1:
- PR.DS-1: Data-at-rest is protected
Incorporates the following subcategorys from the previous version of the framework: PR.DS-1: Data-at-rest is protected, PR.DS-5: Protections against data leaks are implemented, PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity, PR.PT-2: Removable media is protected and its use restricted according to policy.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
Ex1: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of stored data in files, databases, virtual machine disk images, container images, and other resources
Ex2: Use full disk encryption to protect data stored on user endpoints
Ex3: Confirm the integrity of software by validating signatures
Ex4: Restrict the use of removable media to prevent data exfiltration
Ex5: Physically secure removable media containing unencrypted sensitive information, such as within locked offices or file cabinets
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
CA-3: Information Exchange
Approve and manage the exchange of information between the system and other systems using [Assignment (one or more): interconnection security agreements, information exchange security agreements, memoranda of understanding or agreement, service level agreements, user agreements, non-disclosure agreements, [Assignment: organization-defined type of agreement] ]; Document, as part of each exchange agreement, the interface characteristics, security and…
CP-9: System Backup
Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency]; Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency]; Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency] ; and Protect the confidentiality, integrity, and availability of backup information.
MP-8: Media Downgrading
Establish [Assignment: organization-defined system media downgrading process] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category or classification of the information; Verify that the system media downgrading process is commensurate with the security category and/or classification level of the information to be removed and the access authorizations of the potential…
SC-4: Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
SC-7: Boundary Protection
Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; Implement subnetworks for publicly accessible system components that are [Assignment: physically, logically] separated from internal organizational networks; and Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged…
SC-12: Cryptographic Key Establishment and Management
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements].
SC-13: Cryptographic Protection
Determine the [Assignment: organization-defined cryptographic uses] ; and Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography].
SC-28: Protection of Information at Rest
Protect the [Assignment (one or more): confidentiality, integrity] of the following information at rest: [Assignment: organization-defined information at rest].
SC-32: System Partitioning
Partition the system into [Assignment: organization-defined system components] residing in separate [Assignment: physical, logical] domains or environments based on [Assignment: organization-defined circumstances for the physical or logical separation of components].
SC-39: Process Isolation
Maintain a separate execution domain for each executing system process.
SC-43: Usage Restrictions
Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined components] ; and Authorize, monitor, and control the use of such components within the system.
SI-3: Malicious Code Protection
Implement [Assignment (one or more): signature-based, non-signature-based] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code; Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures; Configure malicious code protection mechanisms to: Perform periodic scans of the system…
SI-4: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives] ; and Unauthorized local, network, and remote connections; Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; Invoke internal monitoring capabilities or deploy monitoring devices:…
SI-7: Software, Firmware, and Information Integrity
Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Assignment: organization-defined software, firmware, and information] ; and Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Assignment: organization-defined actions].
NIST SP 800-171 Revision 3.0
03.08.09: System Backup — Cryptographic Protection
Protect the confidentiality of backup information. Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI at backup storage locations.
03.12.05: Information Exchange
Approve and manage the exchange of CUI between the system and other systems using [Selection (one or more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements; other types of agreements]. Document interface characteristics, security requirements, and responsibilities for each system as part of the exchange…
03.13.01: Boundary Protection
Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. Connect to external systems only through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational…
03.13.04: Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
03.13.06: Network Communications — Deny by Default — Allow by Exception
Deny network communications traffic by default, and allow network communications traffic by exception.
03.13.08: Transmission and Storage Confidentiality
Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI during transmission and while in storage.
03.13.10: Cryptographic Key Establishment and Management
Establish and manage cryptographic keys in the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].
03.13.11: Cryptographic Protection
Implement the following types of cryptography to protect the confidentiality of CUI: [Assignment: organization-defined types of cryptography].
03.14.02: Malicious Code Protection
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures. Configure malicious code protection mechanisms to: Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from…
03.14.06: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.
Cloud Controls Matrix v4.0
BCR-08: Backup
Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.
CEK-03: Data Encryption
Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.
CEK-04: Encryption Algorithm
Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.
CEK-18: Key Archival
Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.
CEK-19: Key Compromise
Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.
DCS-04: Secure Media Transportation Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure transportation of physical media. Review and update the policies and procedures at least annually.
DSP-17: Sensitive Data Protection
Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.
HRS-04: Remote and Home Working Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
LOG-02: Audit Logs Protection
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
LOG-09: Log Protection
The information system protects audit records from unauthorized access, modification, and deletion.
UEM-05: Endpoint Management
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-08: Storage Encryption
Protect information from unauthorized disclosure on managed endpoint devices with storage encryption.
Critical Security Controls Version 8.1
3.11: Encrypt Sensitive Data at Rest
Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.