Controls / Other controls proposal forms ask about
Laptops, phones and removable media that hold sensitive data are encrypted
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: encrypt laptops, phones and removable media that hold sensitive data.
In Australia
No Essential Eight requirement covers this control; in Australia it is on the schedule as a condition beyond the core list.
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 3.6 CIS Controls v8.1 | Encrypt Data on End-User Devices Encrypt the data held on end-user devices that store sensitive data. (The held text goes on to give examples that name commercial products; they are left out here.) evidence an assessor asks for Endpoint encryption policy for the built-in disk encryption of each operating system; Encryption compliance report listing unencrypted end-user devices and remediation; MDM or endpoint management encryption status report for laptops and desktops holding sensitive data; Recovery key escrow records showing keys stored centrally for each encrypted device; Build standard showing encryption enabled before a device is issued |
| CIS 3.9 CIS Controls v8.1 | Encrypt data on removable media. evidence an assessor asks for Inventory of approved encrypted USB devices issued to staff, with serial numbers, holders and the encryption algorithm used; Data protection standard requiring encryption of any enterprise data written to removable media, with the approved tools and exemption process; Endpoint or device management policy forcing encryption before writes to USB drives; Device control logs showing unencrypted removable media blocked or set to read-only |
| PR.DS-01 NIST CSF 2.0 | The confidentiality, integrity, and availability of data-at-rest are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Data at rest encryption inventory by store type; Key management standards and rotation evidence; Storage configuration baselines with attestation; Sensitive data discovery findings remediated; Audit findings on data at rest protection |
FTC Safeguards Rule, when it applies
Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 314.4(c)(3) FTC Safeguards Rule (add-on) | 314.4(c)(3) Encryption in transit and at rest All customer information held or transmitted by the institution is protected by encryption both in transit over external networks and at rest; where the institution determines encryption is infeasible in either case, it may instead secure the information by effective alternative compensating controls reviewed and approved by the Qualified Individual. evidence an assessor asks for Encryption standards and coverage for data at rest and in transit over external networks; Qualified Individual's written approval of any compensating control with the infeasibility determination |
HIPAA Security Rule, when it applies
HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.312(a)(2)(iv) HIPAA Security Rule (add-on) | Encryption and Decryption (Addressable) Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57. evidence an assessor asks for Encryption standard; FIPS 140 validation references; Key management procedures; Database, file, and endpoint encryption coverage report |
23 NYCRR 500, when it applies
Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 500.15 23 NYCRR 500 (add-on) | Encryption of Nonpublic Information Implement controls including encryption to protect Nonpublic Information held or transmitted by the Covered Entity in transit over external networks and at rest. Where encryption at rest is infeasible, CISO may approve effective alternative compensating controls, reviewed at least annually. evidence an assessor asks for Encryption standards and approved algorithms list; TLS configuration scans for external endpoints; At-rest encryption coverage report by data store; Key management procedures and HSM evidence; CISO-approved compensating control register for at-rest exceptions with annual review; Discovery scans for unencrypted Nonpublic Information; Email and file transfer encryption configuration |
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.24 ISO/IEC 27001:2022 (lens) | Use of cryptography The organization is to define and apply rules for using cryptography effectively, key management included. Purpose (stated in ISO/IEC 27002:2022): makes cryptography work correctly to keep information confidential, genuine or unaltered as business, security and legal needs require. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.24. evidence an assessor asks for Statement of Applicability entry for control A.8.24, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification; Key management procedures covering generation, distribution, storage, rotation, revocation, recovery, backup, destruction and activation periods; Key inventory or HSM and key management service records with logs of key management activity; Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.