Requirement

Data-at-rest must be encrypted using state-of-the-art encryption algorithms.

Acceptance Criteria

  • All data in databases and backups is encrypted
  • Encryption uses proven algorithms from established vendors or open-source projects
  • Minimum encryption standard: AES-256 or equivalent current best practice