FedRAMP Controls / SC
SC-28 Protection of Information at Rest
Family SC
Baselines moderate
Mapped KSIs 0
Control statement
Protect the {{ insert: param, sc-28_odp.01 }} of the following information at rest: {{ insert: param, sc-28_odp.02 }}.
Guidance: The organization supports the capability to use cryptographic mechanisms to protect information at rest.
Guidance: When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured.
Guidance: Note that this enhancement requires the use of cryptography in accordance with SC-13. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
No 20x Key Security Indicators map to this control in the current catalog version.