SC-28 (1) - Cryptographic Protection [FSv1.1]

This control is based on IBM Cloud Framework for Financial Services v1.1.

Control requirements

SC-28 (1) - 0
The information system implements cryptographic mechanisms to prevent unauthorized disclosure and modification of [IBM Assignment: confidential customer data] on [IBM Assignment: organization-defined information system components including portable computers, mobile devices, and electronic removable media].

Implementation guidance

See the resources that follow to learn more about how to implement this control.

NIST supplemental guidance

Selection of cryptographic mechanisms is based on the need to protect the confidentiality and integrity of organizational information. The strength of mechanism is commensurate with the security category and/or classification of the information. This control enhancement applies to significant concentrations of digital media in organizational areas designated for media storage and also to limited quantities of media generally associated with information system components in operational environments (e.g., portable storage devices, mobile devices). Organizations have the flexibility to either encrypt all information on storage devices (i.e., full disk encryption) or encrypt specific data structures (e.g., files, records, or fields). Organizations employing cryptographic mechanisms to protect information at rest also consider cryptographic key management solutions.