500.15(a)—500.15(a)
>Control Description
As part of its cybersecurity program, each covered entity shall implement a written policy requiring encryption that meets industry standards, to protect nonpublic information held or transmitted by the covered entity both in transit over external networks and at rest.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.