SV-278009r1211149_rule
V-278009
SRG-OS-000185-GPOS-00079
WN25-00-000250
CAT I
10
Configure systems that require data-at-rest protections to employ encryption to protect the confidentiality and integrity of all persistent user-generated data and operating system-specific configuration data.
The encryption method implemented must use FIPS-compliant algorithms.
Note: If there is a documented and approved reason to omit data-at-rest encryption at the operating system level, such as encryption provided by a hypervisor or a disk storage array in a virtualized environment, this requirement is not applicable.
Verify systems that require additional protections due to factors such as inadequate physical protection or sensitivity of the data employ encryption to protect the confidentiality and integrity of all information at rest.
If there is no evidence that persistent user-generated data and operating system-specific configuration data are encrypted, this is a finding.
V-278009
False
WN25-00-000250
Note: If there is a documented and approved reason to omit data-at-rest encryption at the operating system level, such as encryption provided by a hypervisor or a disk storage array in a virtualized environment, this requirement is not applicable.
Verify systems that require additional protections due to factors such as inadequate physical protection or sensitivity of the data employ encryption to protect the confidentiality and integrity of all information at rest.
If there is no evidence that persistent user-generated data and operating system-specific configuration data are encrypted, this is a finding.
M
5719