Frameworks / NIST SP 800-66 Rev 2 / 164.312(a)(2)(iv) NIST SP 800-66 Rev 2
Technical
NIST SP 800-66 Rev 2 164.312(a)(2)(iv): Encryption and Decryption (Addressable) Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 60 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 1.2.6 Security features for insecure services in use 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 2.2.6 2.2.6 System security parameters configured against misuse 3.5.1 3.5.1 Stored PAN rendered unreadable 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse 3.7.1 3.7.1 Generation of strong cryptographic keys AC-19(5) Full Device or Container-Based Encryption SC-12 Cryptographic Key Establishment and Management SC-13 Cryptographic Protection SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection AC-19(5) Full Device or Container-Based Encryption SC-12 Cryptographic Key Establishment and Management SC-13 Cryptographic Protection SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required ASBv3-DP-6 Use a secure key management process BR-2 Protect backup and recovery data DP-4 Enable data at rest encryption by default 03.01.18 Access Control for Mobile Devices 03.08.09 System Backup - Cryptographic Protection 03.13.10 Cryptographic Key Establishment and Management 03.13.11 Cryptographic Protection SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.6 Encrypt Data on End-User Devices CIS-3.9 Encrypt Data on Removable Media C5-CRY-01 Policy for the use of encryption procedures and key management C5-CRY-03 Encryption of sensitive data for storage 8.24 Use of cryptography 8.9 Configuration management ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost CBPR-PR-30 Specific proportional safeguards in place AUCDR-IS-2 Secure the network and systems within the data environment 6.7.1 Cryptographic controls NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technical Query this from an agent The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.