ATO Digital Service Provider (DSP) Operational Security Framework
Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework SEC.EAR: Encryption at rest of in-scope data, or the four compensating controls

DSPs encrypt data stored for tax, accounting, payroll, business registry and superannuation transactions, including personally identifiable information, at the disk, container, application or database level, or by partial encryption at block, field or column level provided it covers all such data, using an approved algorithm (AES with 128, 192 or 256-bit keys) under the Australian Government guidelines for using cryptography. Where encryption at rest is not viable, all four compensating controls are required: role-based access controls with active logging and monitoring; least-privilege access to databases; separation of hosts and network segregation or micro-segmentation; intrusion prevention and detection. Network segmentation is recommended in addition where encryption is in place. For categories D and E the DSP should apply it where it controls the capability.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISM-0459 Full disk or partial encryption at rest
  • ISM-1080 Approved algorithms for media encryption

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.