Frameworks / Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 / CCM-CEK-03 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
CEK - Cryptography, Encryption & Key Management
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-CEK-03: Data Encryption Apply cryptographic protection to stored data and to data moving across networks, using libraries that hold certification against an approved standard.
Maintained by Gerard Blokdyk · Control text last updated 19 August 2026 What else in your programme already covers this This control maps to 78 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-17(2) Protection of Confidentiality and Integrity Using Encryption CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) SC-13 Cryptographic Protection SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection AC-17(2) Protection of Confidentiality and Integrity Using Encryption CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) SC-13 Cryptographic Protection SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection 2.2.7 2.2.7 Non-console administrative access encrypted 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted 3.5.1 3.5.1 Stored PAN rendered unreadable 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography C5-COS-08 Policies for data transmission C5-CRY-02 Encryption of data for transmission (transport encryption) C5-CRY-03 Encryption of sensitive data for storage C5-OPS-09 Data Backup and Recovery - Storage CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.6 Encrypt Data on End-User Devices CIS-3.9 Encrypt Data on Removable Media ANSSI-HYG-11 Protect Passwords Stored on Systems ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost BR-2 Protect backup and recovery data DP-3 Encrypt sensitive data in transit DP-4 Enable data at rest encryption by default 6.11.1 Security requirements of information systems 6.7.1 Cryptographic controls 7.4.9 PII transmission controls NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected 03.08.09 System Backup - Cryptographic Protection 03.13.08 Transmission Confidentiality and Integrity 03.13.11 Cryptographic Protection CBPR-PR-27 Physical, technical and administrative safeguards CBPR-PR-30 Specific proportional safeguards in place ASD37-17 TLS encryption between email servers (Limited) ASD37-23 Protect authentication credentials (Excellent) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal AUCDR-IS-2 Secure the network and systems within the data environment APP-11 APP 11 - Security of personal information Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CEK - Cryptography, Encryption & Key Management You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done? Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-CEK-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.