DATA-3 File System Encryption

Estimated reading: 2 minutes 1665 views

What is DATA-3 File System Encryption Control?

File system encryption protects individual files or file systems by encrypting them with a specific key and making them accessible only to authorized persons.

There are no mandatory encryption mechanisms to use; this is left to the discretion of each company. Therefore, as an organization, you can edit the TrustCloud control ‘File systems for databases and other sensitive data storage require at least block-level encryption’ to match your unique encryption mechanisms.

Available tools in the marketplace

 No tool recommendation for this section

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version:

Control implementation

NOTE: This control is 100% automated by TrustCloud. Connect your system to enjoy the benefits of automation.

To implement this control manually, 

Enable encryption on file storage systems using the most recent encryption technologies.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide a screenshot of the file storage configuration settings showing that encryption is enabled.

Evidence example

For the suggested action, an example is provided below:

  1. Provide a screenshot of the file storage configuration settings showing that encryption is enabled.
    The following screenshot shows an encryption configuration that has encryption enabled.
    NOTE: This example illustrates the configuration evidence that an auditor will expect. This is not necessarily shown as block-level encryption. There is no mandatory level of encryption. Just provide a screenshot of your encryption configuration.
    Google search
    DATA 3 File System Encryption

Join the conversation

You might also be interested in

Documentation Templates

Documentation Templates are documents that provide a content outline to meet certain documentation needs....

Backup policy template – Download for free

The Data Backup Plan template helps you document in detail the data backup needs...

HR-13 Employee Handbook/Code of Conduct

HR-13 Employee Handbook or Code of Conduct communicates the organization’s values and ethics. It...

AUTH-1 Single Sign On (SSO)

Single Sign On (SSO) Control is a best practice recommendation for critical systems....

Security Incident Report Template

The Security Incident Report template helps you document the steps used to assess and...

BIZOPS-6 Disaster Recovery Testing

BIZOPS-6 Disaster Recovery Testing control refers to the exercise of identifying the critical systems...

PDP-10 SDLC – Separation of environments

PDP-10 SDLC Separation of Environments is important to maintain separate environments to develop, test,...

Privacy Committee Charter Template

Privacy Committee Charter serves as a foundational document, establishing the framework for the committee's...