Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.DS-01 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected The confidentiality, integrity, and availability of data-at-rest are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 176 controls across 47 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.8 1.2.8 NSC configuration files secured and consistent 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 10.3.2 10.3.2 Audit log files protected from modification 10.3.4 10.3.4 File integrity monitoring on audit logs 10.6.3 10.6.3 Time sync configuration and time data protected 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted 3.5.1 3.5.1 Stored PAN rendered unreadable 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 3.7.3 3.7.3 Secure storage of cryptographic keys 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 9.4.3 9.4.3 Securing media sent outside the facility 9.4.7 9.4.7 Destruction of electronic media 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse 3.7.1 3.7.1 Generation of strong cryptographic keys CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.12 Segment Data Processing and Storage Based on Sensitivity CIS-3.13 Deploy a Data Loss Prevention Solution CIS-3.3 Configure Data Access Control Lists CIS-3.5 Securely Dispose of Data CIS-3.6 Encrypt Data on End-User Devices CIS-3.7 Establish and Maintain a Data Classification Scheme CIS-3.9 Encrypt Data on Removable Media 5.33 Protection of records 7.10 Storage media 7.9 Security of assets off-premises 8.11 Data masking 8.12 Data leakage prevention 8.13 Information backup 8.24 Use of cryptography 8.3 Information access restriction 8.33 Test information AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-19(5) Full Device or Container-Based Encryption AU-9 Protection of Audit Information CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) MP-4 Media Storage MP-6 Media Sanitization SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-19(5) Full Device or Container-Based Encryption AU-9 Protection of Audit Information CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) MP-4 Media Storage MP-6 Media Sanitization SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection 5.12 Classification of information 5.33 Protection of records 7.10 Storage media 7.9 Security of assets off-premises 8.1 User endpoint devices 8.12 Data leakage prevention 8.24 Use of cryptography 8.3 Information access restriction SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-C1.2 C1.2 Disposing of confidential information SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.5 CC6.5 Protecting data on assets until disposal SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs ADMF-5.1 Implement risk-based protection controls ADMF-5.2 Apply technical, procedural and physical safeguards ADMF-5.3 Protect data across the data lifecycle ADMF-5.4 Build a data protection control matrix C5-CRY-01 Policy for the use of encryption procedures and key management C5-CRY-03 Encryption of sensitive data for storage C5-CRY-04 Secure key management C5-IDM-07 Access to cloud customer data PR.DS-1 PR.DS-1: Data-at-rest is protected PR.DS-5 PR.DS-5: Protections against data leaks are implemented PR.DS-6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity PR.PT-2 PR.PT-2: Removable media is protected and its use restricted according to policy PR.DS-1 PR.DS-1: Data-at-rest is protected PR.DS-5 PR.DS-5: Protections against data leaks are implemented PR.DS-6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity PR.PT-2 PR.PT-2: Removable media is protected and its use restricted according to policy ISM-0459 Full disk or partial encryption at rest ISM-0869 Encrypting mobile device storage ISM-1059 Encrypting data on media ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required ASBv3-DP-6 Use a secure key management process DP-4 Enable data at rest encryption by default BMA-18 Data Classification and Security BMA-19 Data Protection, Governance and Loss Prevention BMA-25 Use of Cryptography ANSSI-HYG-11 Protect Passwords Stored on Systems ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost APPI-A23 Security Control Measures APPI-A46 Security and Proper Handling of Anonymized Personal Information AUCDR-IS-2 Secure the network and systems within the data environment AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data BE-CF-08 Cryptographic protection of data BE-CF-39 Data security lifecycle management 3.14.1e Verify Integrity of Security Critical Software and Firmware 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed ASD37-23 Protect authentication credentials (Excellent) AWWA-3.4 Encryption and Data Protection MYHR-CUD-4 Records not held or taken outside Australia AEO-9 Information Exchange, Access and Confidentiality CIRCIA-2245a Authorized Use, Retention and Digital Security of Reports CA-SB327-1798.91.04a Reasonable Security Feature Requirement ITSG33-MP Media Protection (MP) DSL-Art27 Data Security Management System and Whole-Lifecycle Measures (Art. 27) DODZT-4.5 Data Encryption and Rights Management CDMC-KC9 Security Controls DCAM-8.3 Information Security and Privacy EN303645-5.8 Ensure that personal data is secure Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 176 it maps to, and the evidence behind each claim, over MCP and REST.