Data-at-rest (specifically data in databases and in backups) shall be encrypted using state-of-the-art encryption algorithms from a proven vendor or open-source project - such as AES-256 at the time of writing.