GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-003 Encryption at Rest

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

All sensitive and confidential data stored in databases, object storage, file systems and backup media is encrypted using approved algorithms (minimum AES-256 or equivalent). Encryption is applied at the storage layer, volume or field level as appropriate to the classification and risk.

Rationale

Encryption at rest limits the impact of physical or logical access to storage infrastructure. It is a baseline expectation across all major security frameworks.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.312(a)(2)(iv) is addressable, but the HHS guidance on rendering protected health information unsecured makes encryption at rest the safe harbour that keeps a loss outside the Breach Notification Rule. DAT-003's fixed AES-256 floor is above what the rule names.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (24)

AIS-14AI Cache Protectioninformative
CEK-03Data Protectionfull
CEK-04Encryption Algorithmfull
UEM-08Storage Encryptionpartial
CEK-03Data Protectionfull
CEK-04Encryption Algorithmfull
UEM-08Storage Encryptionpartial
DORA-Art.30.2.cAvailability, authenticity, integrity and confidentiality of datainformative
EU-DA-Art.32.1Measures Preventing Unlawful Third-Country Accessinformative
GDPR-Art.32.1Technical and Organisational Security Measurespartial
GDPR-Art.5.1fIntegrity and Confidentiality (Security Principle)informative
HIPAA-164.312.a.2.ivEncryption and Decryptionfull
HIPAA-164.312.e.2.iIntegrity Controlsinformative
HIPAA-164.312.e.2.iiEncryptioninformative
8.24Use of cryptographyfull
AML.M0012Encrypt Sensitive Informationfull
NIS2-Art.21.2.hUse of Cryptography and Encryptioninformative
NIS2-CIR-12.3Removable Media Policyinformative
NIS2-CIR-9Cryptographyinformative
CP-9(8)System Backup | Cryptographic Protectioninformative
SC-13Cryptographic Protectioninformative
SC-28Protection of Information at Restfull
SC-28(1)Protection of Information at Rest | Cryptographic Protectionfull
CC6.1Logical Access Security Software, Infrastructure, and Architecturespartial

Evidence (2)

configurationtechnicalautomated

Cloud provider storage configuration demonstrating encryption at rest is enabled for all databases, object stores and backup media using approved algorithms.

Example: AWS S3 bucket policy export, RDS instance configuration, or equivalent GCP/Azure output showing server-side encryption enabled (AES-256 or KMS-managed key) for all buckets and database instances in the production account

Test: Query cloud provider APIs or console exports for all storage resources in production. Verify: (1) encryption at rest is enabled on every S3 bucket / Cloud Storage bucket, (2) every RDS / Cloud SQL / Cosmos DB instance has encryption enabled, (3) backup snapshots are encrypted, (4) no unencrypted EBS volumes or equivalent are present in production.

policydocumentmanual

Encryption policy or cryptographic standards document specifying approved algorithms, minimum key lengths, and the requirement to encrypt sensitive data at rest.

Example: Cryptographic Controls Policy or Encryption Standard (Confluence), approved by CISO, specifying AES-256 as minimum, defining scope (databases, object storage, backups, laptops) and referencing FIPS 140-2 or equivalent

Test: Request the encryption policy or cryptographic standard. Verify: (1) names AES-256 (or equivalent) as the minimum approved algorithm, (2) explicitly requires encryption at rest for Confidential and Restricted data, (3) is approved by a named authority and dated within 24 months, (4) scope covers databases, object storage, backups and endpoints.

Questions (2)

boolean

Is all sensitive and confidential data encrypted at rest using an approved algorithm (AES-256 or equivalent) across databases, object storage, file systems and backup media?

Encryption must cover all environments holding sensitive or personal data including production databases, object stores (e.g. S3, Cloud Storage), backup snapshots, and attached volumes. Verify the algorithm meets AES-256 or an equivalent approved standard.

multi

At which layer(s) is encryption at rest applied?

Storage volume encryption (e.g. EBS, persistent disk)Object storage server-side encryption (e.g. S3-SSE, GCS CMEK)Database-level transparent data encryption (TDE)Field-level or application-level encryption for the most sensitive fieldsBackup encryptionNone of the above

A defence-in-depth approach applies encryption at multiple layers. Field-level encryption for highly sensitive fields (e.g. national IDs, payment data) provides the strongest protection against logical access to the database layer.