SC-28(2)—Protection Of Information At Rest
Technical
>Control Description
PROTECTION OF INFORMATION AT REST | OFF-LINE STORAGE The organization removes from online storage and stores off-line in a secure location ⚙organization-defined information.
>Supplemental Guidance
Removing organizational information from online information system storage to off-line storage eliminates the possibility of individuals gaining unauthorized access to the information through a network. Therefore, organizations may choose to move information to off-line storage in lieu of protecting such information in online storage.
>Tailoring Guidance
This security control/enhancement specifies a very specialized and/or advanced capability that is not required for all systems. Consequently, inclusion in a departmental profile is made on a case by case basis.
Ask AI
Configure your API key to use AI features.