{"data":{"id":"SC-28","name":"Protection of Information at Rest","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Protect the [Selection (one or more): confidentiality; integrity] of the following information at rest: [Assignment: organization-defined information at rest].","supplemental_guidance":"Information at rest refers to the state of information when it is not in process or in transit and is located on system components. Such components include internal or external hard disk drives, storage area network devices, or databases. However, the focus of protecting information at rest is not on the type of storage device or frequency of access but rather on the state of the information. Information at rest addresses the confidentiality and integrity of information and covers user information and system information. System-related information that requires protection includes configurations or rule sets for firewalls, intrusion detection and prevention systems, filtering routers, and authentication information. Organizations may employ different mechanisms to achieve confidentiality and integrity protections, including the use of cryptographic mechanisms and file share scanning. Integrity protection can be achieved, for example, by implementing write-once-read-many (WORM) technologies. When adequate protection of information at rest cannot otherwise be achieved, organizations may employ other controls, including frequent scanning to identify malicious code at rest and secure offline storage in lieu of online storage.","enhancements":[{"id":"SC-28(01)","name":"Cryptographic Protection","statement":"Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on [Assignment: organization-defined system components or media]: [Assignment: organization-defined information].","baselines":["moderate","high"]},{"id":"SC-28(02)","name":"Offline Storage","statement":"Remove the following information from online storage and store offline in a secure location: [Assignment: organization-defined information].","baselines":[]},{"id":"SC-28(03)","name":"Cryptographic Keys","statement":"Provide protected storage for cryptographic keys [Selection (one): [Assignment: organization-defined safeguards]; hardware-protected key store].","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-28","name":"Protection of Information at Rest","description":"Protect the [Selection (one or more): confidentiality; integrity] of the following information at rest: [Assignment: organization-defined information at rest].","discussion":"Information at rest refers to the state of information when it is not in process or in transit and is located on system components. Such components include internal or external hard disk drives, storage area network devices, or databases. However, the focus of protecting information at rest is not on the type of storage device or frequency of access but rather on the state of the information. Information at rest addresses the confidentiality and integrity of information and covers user information and system information. System-related information that requires protection includes configurations or rule sets for firewalls, intrusion detection and prevention systems, filtering routers, and authentication information. Organizations may employ different mechanisms to achieve confidentiality and integrity protections, including the use of cryptographic mechanisms and file share scanning. Integrity protection can be achieved, for example, by implementing write-once-read-many (WORM) technologies. When adequate protection of information at rest cannot otherwise be achieved, organizations may employ other controls, including frequent scanning to identify malicious code at rest and secure offline storage in lieu of online storage.","related_controls":["AC-03","AC-04","AC-06","AC-19","CA-07","CM-03","CM-05","CM-06","CP-09","MP-04","MP-05","PE-03","SC-08","SC-12","SC-13","SC-34","SI-03","SI-07","SI-16"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":["A.5.10","A.5.33","A.7.9","A.8.1","A.8.24"],"iso_27002_2022":["6.7","7.9","8.1","8.11","8.24"],"cobit_2019":["APO14"],"pci_dss_v4":["3.1","3.3","3.5"],"nist_csf_2":["PR.DS-01"],"cis_controls_v8":["CIS 3","CIS 3.6","CIS 3.9","CIS 3.11","CIS 4","CIS 11.3"],"soc2_tsc":[],"finos_ccc":["CCC-C02"],"iso_42001_2023":[],"iec_62443":["3-3 SR 4.1"],"asd_e8":[],"nis2":["Art. 21(2)(h)"],"apra_cps_234":["Para 22-23"],"mas_trm":["10","15"],"pra_op_resilience":["SS2/21-11.1"],"bsi_grundschutz":["CON.1","CON.7","OPS.1.2.4","SYS.2.1"],"anssi":["Hygiene.19"],"osfi_b13":[],"finma_circular":[],"gdpr":["Art.5(1)(f)","Art.32(1)(a)","Rec.83"],"dora":["Art.9(3)"],"bio2":["6.7","7.9","8.1","8.11","8.24"],"rbi_csf":["Annex1.15","ITGRCA.16"],"fisc":["FISC.T4","FISC.T5"],"lgpd_bcb":["BCB.Art.3","LGPD.Art.11","LGPD.Art.46"],"hkma_tme1":["TME1.9.1","TME1.9.2","TME1.10.2","TME1.10.3","TME1.11.2","TME1.12.4"],"mlps_2":["8.1.4.7","8.1.4.8","8.2"],"dnb_good_practice":["DNB.12.3"],"cra":["CRA.I.2b","CRA.I.2e"],"swift_cscf":["SWIFT.1.3","SWIFT.2.5A","SWIFT.5.4","SWIFT.6.3"],"cbb_tm":["TM-9"],"cbuae":["CR-5","CR-8"],"nca_ecc":["2-3","2-6","2-7","2-8","4-2"],"qatar_nia":["CS"],"sama_csf":["3.4","4.3"],"uae_ia":["T4","T8"],"bog_cisd":["CISD-V","CISD-VI","CISD-XII"],"bom_ctrm":["3.4","3.10","3.12"],"cbe_csf":["CTO-2","CTO-3"],"cbn_csf":["Part3.3","Part3.4"],"popia":["s19"],"sa_js2":["JS2-8.2","JS2-8.3"],"bcbs_239":["Principle 2","Principle 3"],"bot_cyber":["Ch2.3","Ch2.7"],"cpmi_pfmi":["CG.PR","PFMI.P17"],"eba_ict":["3.4.4"],"ecb_croe":["CROE.2.2.2","CROE.2.3.3"],"ffiec_is":["II.C.13","II.C.13(a)","II.C.18","II.C.19"],"hipaa_sr":["§164.310(c)","§164.310(d)(2)(iv)","§164.312(a)(1)","§164.312(a)(2)(iv)","§164.312(c)(1)","§164.312(c)(2)"],"iosco_cyber":["PROT-3"],"nydfs_500":["500.15"],"sebi_cscrf":["DATALOC","PR.CS","PR.DS"],"cmmc_2":["MP","SC"],"nerc_cip":["CIP-011-3"],"nrc_73_54":["73.54(c)(1)","RG5.71-A-SC"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 8"],"awia":[],"iaea_nss":[],"pci_pts":["C"],"fips_140":["FIPS 140-3 §7.8","FIPS 140-3 §7.9"],"cbest":["CBEST.9"],"tiber_eu":["TIBER.CONF"],"pci_hsm":[],"common_criteria":["CC Part 2 — FCS"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.10(b)","§11.10(c)","§11.70"],"fda_cyber":["SA-2","SA-4"],"hitrust_csf":["01.d","09.f","10.c","13.e"],"iso_27799":["6.3","10.1","12.3","H.4"],"lloyds_ms":[],"naic_ds":["4-encryption","4B"],"nhs_dspt":["NDG-1.1","NDG-9.6","NDG-9.7"],"pra_ss1_23":["P-IT.3"],"solvency_ii":["Art.49(3)","DR.266-DataSec","EIOPA-Cloud-GL9","EIOPA-ICT-4.7"],"owasp_masvs_v2":["MASVS-STORAGE-1","MASVS-STORAGE-2"],"csa_ccm_v4":["CEK-03","DSP-07","DSP-17","UEM-08"],"csa_aicm":["CEK-03","DSP-07","DSP-17","UEM-08"],"ccss_v9":["1.01.1","1.01.4","1.03.1","1.03.6","1.05.5"],"mica":["Art.40(1)","Art.55(1)","Art.62(9)","Art.63(1)","Art.67(1)","Art.97(1)","Art.98(1)"],"basel_sco60":[],"bssc":["GSP-09","GSP-13"],"sec_custody_digital":["SEC-CD-08"],"dpdpa":["Act.8(5)","Rules.6(1)(a)","Rules.Sch1.B.7","Rules.Sch2"]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting credential stores at rest, including SAM databases, NTDS.dit files, and cached credential storage, renders dumped credential data unreadable without the corresponding decryption keys."},{"id":"T1005","name":"Data from Local System","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting sensitive data at rest on local file systems ensures that even if adversaries gain file-level access, the collected data remains cryptographically protected and unusable."},{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encryption of data stored on removable media ensures that physically exfiltrated storage devices contain only ciphertext, preventing adversary access to plaintext data without decryption keys."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Encrypting information at rest ensures that data staged for exfiltration over C2 channels is in ciphertext form, requiring decryption keys that adversaries are unlikely to possess."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Protection of information at rest through encryption ensures that data copied for exfiltration via alternative protocols remains encrypted, limiting the value of successfully exfiltrated ciphertext."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Encrypting data at rest on systems with physical media access ensures that data copied to removable devices for physical exfiltration remains cryptographically protected."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Encrypting stored credentials and authentication databases at rest limits the utility of valid account credentials obtained through file system access, as the credential material is ciphertext."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting information repository data at rest ensures that adversaries accessing wikis, document stores, or databases cannot read content without possessing the appropriate decryption keys."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encryption of cloud storage objects at rest with customer-managed keys ensures that even if bucket policies are misconfigured, adversary-accessed data remains encrypted and unusable."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting stored credentials at rest, including password files, private keys, and credential databases, prevents adversaries from reading unsecured credential material through file system access."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Integrity protection mechanisms for information at rest detect unauthorized data modifications through cryptographic checksums and authenticated encryption, preventing undetected data manipulation."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Encrypting data at rest ensures that information staged for exfiltration over web services is cryptographically protected, limiting the intelligence value of successfully exfiltrated content."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Encrypting network device configurations at rest prevents adversaries who bridge network boundaries from reading sensitive configuration data stored on compromised network infrastructure."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting configuration repository data at rest ensures that SNMP MIB values and device configuration files remain protected even if adversaries gain access to configuration storage."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Credential Guard and memory encryption mechanisms protect LSASS credential material at rest in memory, preventing credential dumping tools from reading plaintext passwords and hashes."},{"id":"T1003.002","name":"Security Account Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting the SAM database with SYSKEY and additional cryptographic protections ensures that extracted SAM hive files contain encrypted credential data that resists offline extraction."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting the NTDS.dit database at rest through BitLocker or database-level encryption ensures that copies of the Active Directory database contain encrypted credential hashes."},{"id":"T1003.004","name":"LSA Secrets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encryption of LSA Secrets at rest in the registry protects cached service account credentials and machine secrets from extraction by adversaries with registry access."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting cached domain credentials at rest with strong cryptographic algorithms limits adversary ability to extract and crack DCC2 hashes from offline system access."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting domain controller data at rest ensures that even if replication data is intercepted through DCSync, the credential material remains cryptographically protected."},{"id":"T1003.007","name":"Proc Filesystem","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Memory encryption technologies and confidential computing protections safeguard credential data stored in process memory from extraction through /proc filesystem reads by adversaries on Linux systems."},{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong encryption of the /etc/shadow file with modern hashing algorithms (SHA-512, bcrypt) ensures that extracted password hashes resist offline brute-force cracking attempts."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Encrypting data at rest ensures that information collected for exfiltration over asymmetric-encrypted non-C2 protocols is already in ciphertext form, providing defense-in-depth against data theft."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Information encryption at rest ensures that data exfiltrated over unencrypted protocols still requires decryption keys that adversaries lack, limiting the value of intercepted plaintext transmissions."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Encrypting data on systems with USB access ensures that information copied to USB devices for physical exfiltration remains cryptographically protected and unreadable without proper keys."},{"id":"T1078.001","name":"Default Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Encrypting stored default account credentials at rest prevents adversaries from harvesting factory-set passwords from configuration files and databases on newly provisioned systems."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Encrypting local credential stores and password databases at rest limits adversary extraction of local account credentials through file system access to encrypted systems."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Encrypting cloud credential stores and token caches at rest prevents adversaries from reading cloud account credentials stored on compromised endpoints or cloud infrastructure."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting Confluence data at rest ensures that adversaries accessing the underlying database or file storage cannot read organizational knowledge base content without decryption keys."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting SharePoint document libraries and site collections at rest protects organizational documents from being read even if adversaries gain access to storage infrastructure."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting CRM database storage at rest ensures that adversary access to underlying data stores does not expose customer relationship data without appropriate decryption keys."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting messaging application data at rest protects chat histories, file attachments, and channel content from unauthorized access through storage-level compromise."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Encrypting application access token stores at rest prevents adversaries from extracting usable OAuth tokens from local caches and credential storage files."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting files that may contain credentials ensures that passwords, API keys, and secrets stored in configuration files remain protected even if file-level access is compromised."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting registry-stored credentials at rest through DPAPI or similar mechanisms ensures that credential values in registry keys are ciphertext requiring additional keys to decrypt."},{"id":"T1552.003","name":"Bash History","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting bash history files or configuring them to exclude sensitive commands prevents adversary extraction of credentials inadvertently typed into command-line history."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Encrypting private key files at rest with passphrase protection ensures that stolen key files require additional authentication before they can be used for access."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Integrity protection through authenticated encryption of stored data detects unauthorized modifications, as adversary changes to encrypted data will fail integrity verification checks."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Memory integrity protection mechanisms detect unauthorized runtime data modifications through hardware-backed integrity verification, preventing undetected manipulation of live application data."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Encrypting network device configuration data at rest ensures that NAT rules and routing configurations exposed through boundary bridging remain cryptographically protected."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting SNMP MIB data and device configuration stores at rest prevents adversaries from reading usable configuration information from SNMP dumps of protected devices."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting network device configurations at rest ensures that full device configuration dumps obtained through unauthorized access contain encrypted data requiring additional keys to decrypt."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: iso_27001_2022 A.5.10, A.5.33 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-015","SP-028","SP-029","SP-030","SP-034","SP-037","SP-039","SP-040","SP-041","SP-042","SP-047","SP-049","SP-050","SP-051","SP-052","SP-053","SP-054"]}}