DSPs encrypt data stored for tax, accounting, payroll, business registry and superannuation transactions, including personally identifiable information, at the disk, container, application or database level, or by partial encryption at block, field or column level provided it covers all such data, using an approved algorithm (AES with 128, 192 or 256-bit keys) under the Australian Government guidelines for using cryptography. Where encryption at rest is not viable, all four compensating controls are required: role-based access controls with active logging and monitoring; least-privilege access to databases; separation of hosts and network segregation or micro-segmentation; intrusion prevention and detection. Network segmentation is recommended in addition where encryption is in place. For categories D and E the DSP should apply it where it controls the capability.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.