NIST 800-53 Rev 5

424 controls available

SC-28moderatehigh

Protection of Information at Rest

System and Communications Protection

Control Statement

Protect the {{ insert: param, sc-28_odp.01 }} of the following information at rest: {{ insert: param, sc-28_odp.02 }}.

Discussion

Information at rest refers to the state of information when it is not in process or in transit and is located on system components. Such components include internal or external hard disk drives, storage area network devices, or databases. However, the focus of protecting information at rest is not on the type of storage device or frequency of access but rather on the state of the information. Information at rest addresses the confidentiality and integrity of information and covers user information and system information. System-related information that requires protection includes configurations or rule sets for firewalls, intrusion detection and prevention systems, filtering routers, and authentication information. Organizations may employ different mechanisms to achieve confidentiality and integrity protections, including the use of cryptographic mechanisms and file share scanning. Integrity protection can be achieved, for example, by implementing write-once-read-many (WORM) technologies. When adequate protection of information at rest cannot otherwise be achieved, organizations may employ other controls, including frequent scanning to identify malicious code at rest and secure offline storage in lieu of online storage.

Framework
NIST SP 800-53 Rev 5
Family
System and Communications Protection
Baselines
moderate, high

Related Frameworks

3 paths across 2 frameworks
NIST 800-1711 mapping
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI2 mappings
CCI-001199
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002472
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

160 STIGs reach this control through 11 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

45 STIGs
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-193 of 216 findings match
Show 37 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-172 of 448 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-191 of 103 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-061 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-161 of 283 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-131 of 375 findings match

Operating System — Mainframe

9 STIGs
Mainframe Product Security Requirements Guide
V3R42025-09-104 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-054 of 193 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-091 of 225 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-091 of 222 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-091 of 230 findings match
Show 1 more STIG in this category →

Operating System — Mobile

13 STIGs

Network Device

17 STIGs
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-195 of 119 findings match
BIND 9.x Security Technical Implementation Guide
V3R22026-02-253 of 73 findings match
BIND 9.x Security Technical Implementation Guide
22024-02-153 of 70 findings match
AAA Services Security Requirements Guide
V2R22024-12-041 of 77 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-151 of 160 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-111 of 53 findings match
Show 9 more STIGs in this category →
Network Device Management Security Requirements Guide
V5R32025-02-111 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-101 of 105 findings match

Database

26 STIGs
Database Security Requirements Guide
V4R52026-02-264 of 142 findings match
Database Security Requirements Guide
42024-12-044 of 142 findings match
Show 18 more STIGs in this category →

Web / Application Server

19 STIGs
Application Server Security Requirements Guide
V4R42025-09-105 of 137 findings match
Application Server Security Requirements Guide
42025-02-115 of 128 findings match
Web Server Security Requirements Guide
V4R42025-09-103 of 126 findings match
Show 11 more STIGs in this category →
Web Server Security Requirements Guide
42025-02-123 of 124 findings match

Virtualization / Container

13 STIGs
Virtual Machine Manager Security Requirements Guide
22024-12-064 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-104 of 198 findings match
Container Platform Security Requirements Guide
V2R42025-09-102 of 188 findings match
Container Platform Security Requirements Guide
22025-05-152 of 187 findings match
Kubernetes Security Technical Implementation Guide
V2R62026-02-121 of 92 findings match
Show 5 more STIGs in this category →

Endpoint Security Management

6 STIGs

Productivity Application

3 STIGs

Uncategorized

2 STIGs