Requirement
Data-at-rest must be encrypted using state-of-the-art encryption algorithms.
Acceptance Criteria
- All data in databases and backups is encrypted
- Encryption uses proven algorithms from established vendors or open-source projects
- Minimum encryption standard: AES-256 or equivalent current best practice