Regulations and Standards: Where Encryption Applies
There are a significant number of worldwide regulations that relate to protection of private and sensitive data. Some are focused on protection of specific industry information, where others are more concerned with disclosure of data loss incidents and privacy attributes. Most of today's standards and compliance regulations are concerned with the protection of private data at rest, during transactions, and while it traverses network connections. By determining what data you are required to protect, locating the data at rest and in transit, implementing the appropriate encryption technologies, you can significantly improve your overall security posture while complying with any number of data privacy regulations. This paper describes the types of data under regulation and describe basic best practices for implementing appropriate encryption technologies.
|