|
controlSC-28

Protection of Information at Rest (SC-28)

Protect the [organization-defined] of the following information at rest: [organization-defined].

Security Baselines

MODERATEHIGHLOW
communicationsencryptionboundary-protectionnetwork

Why These Connect

Maps To3

These are equivalent or closely aligned requirements in other frameworks.

Baselined In2

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports30

These related controls work together — a change to one may affect the others.

Mitigates2

This control helps defend against or reduce the risk of the linked threat technique.

Enhances3

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(3)

PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(2)

SelectionSelection (one-or-more): confidentiality / integrity
Assignmentorganization-defined information at rest

Control Enhancements(3)