Apply Section 5.3 cryptography including: encryption of data at rest (AES-256 + FIPS 140-3 validated modules + full disk encryption + file-level encryption + database encryption) + data in transit (TLS 1.3 + IPsec + SSH 2.0 + S/MIME + PGP) + key management per NIST SP 800-57 + NIST SP 800-152 + key lifecycle (generation + storage + distribution + rotation + revocation + escrow + destruction) + certificate management (X.509 + ACME + Let's Encrypt + DigiCert + private CA) + Post-Quantum Cryptography migration per FIPS 203/204/205 (ML-KEM + ML-DSA + SLH-DSA).
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 76 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.