SC-28 (1) - Cryptographic Protection [FSv1.1]
This control is based on IBM Cloud Framework for Financial Services v1.1.
Control requirements
- SC-28 (1) - 0
- The information system implements cryptographic mechanisms to prevent unauthorized disclosure and modification of [IBM Assignment: confidential customer data] on [IBM Assignment: organization-defined information system components including portable computers, mobile devices, and electronic removable media].
Implementation guidance
See the resources that follow to learn more about how to implement this control.
NIST supplemental guidance
Selection of cryptographic mechanisms is based on the need to protect the confidentiality and integrity of organizational information. The strength of mechanism is commensurate with the security category and/or classification of the information. This control enhancement applies to significant concentrations of digital media in organizational areas designated for media storage and also to limited quantities of media generally associated with information system components in operational environments (e.g., portable storage devices, mobile devices). Organizations have the flexibility to either encrypt all information on storage devices (i.e., full disk encryption) or encrypt specific data structures (e.g., files, records, or fields). Organizations employing cryptographic mechanisms to protect information at rest also consider cryptographic key management solutions.