FedRAMP Controls / SC

SC-28 Protection of Information at Rest

Family SC
Baselines moderate
Mapped KSIs 0

Control statement

Protect the {{ insert: param, sc-28_odp.01 }} of the following information at rest: {{ insert: param, sc-28_odp.02 }}.
        Guidance: The organization supports the capability to use cryptographic mechanisms to protect information at rest.
        Guidance: When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured.
        Guidance: Note that this enhancement requires the use of cryptography in accordance with SC-13.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

No 20x Key Security Indicators map to this control in the current catalog version.