What Guide to Storage Encryption Technologies for End User Devices requires
This publication assists organizations in understanding, planning, implementing, and maintaining storage encryption technologies for end user devices, including personal computers, consumer devices like smart phones, and removable storage media. It addresses threats to information confidentiality such as device loss or theft, insider attacks, and malware. The primary security controls discussed for restricting access to sensitive information, particularly personally identifiable information (PII), are encryption and authentication. The guide provides practical, real-world guidance for three classes of storage encryption: full disk encryption, volume and virtual disk encryption, and file/folder encryption. It makes recommendations for implementing and using each type. Key recommendations for Federal departments and agencies include using centralized management for most deployments to ensure policy verification, key management, and data recovery. Organizations should ensure all cryptographic keys are secured and managed properly throughout their lifecycle, from generation to destruction, to support data recovery. Appropriate user authenticators should be selected, with a preference for two-factor authentication, as using a single-factor authenticator for both OS login and encryption significantly weakens protection. Storage encryption by itself is considered insufficient; it must be complemented by other security controls, such as securing device operating systems, revising organizational policies, and making users aware of their responsibilities.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-111.pdf
SHA-256 integrity: 9d07074ce7982cc98180ea8359737056a406cdf76814f71a71ed871e64f9d2fe
Primary Citations — 8 traced to source
- {"citation":"Executive Summary","text":"Organizations should use centralized management for all deployments of storage encryption except for standalone deployments and very small-scale deployments."}
- {"citation":"Executive Summary","text":"Organizations should ensure that all cryptographic keys used in a storage encryption solution are secured and managed properly to support the security of the solution."}
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access