All data at rest is protected for selected data categories
Information can be categorized (as referenced in ASSET-2c) according to several security considerations including sensitivity, value, criticality, or legal requirements. This practice extends the architectural tactics for data at rest noted in ARCHITECTURE-5a, such as authentication (e.g., credential management, digital certificates, biometric identification, multifactor authentication), authorization (e.g., access control mechanisms), and protection (e.g., encryption and data masking). Architectural data protection tactics may also include, for example, the use of a secure data access layer instead of permitting direct access to data stores.
Related Practices · Input From: Implementing ASSET-2c provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ARCHITECTURE-5a, ARCHITECTURE-5b, ARCHITECTURE-5c, ARCHITECTURE-5d, ARCHITECTURE-5e, ARCHITECTURE-5f, ARCHITECTURE-5g, ARCHITECTURE-5h.