Encryption at Rest
Encryption at rest is the practice of encrypting data while it is stored, for example on a disk, solid-state drive, or backup media, so that the stored information cannot be read by someone who gains access to the storage without the decryption key. Its purpose is to protect data from outcomes such as data breaches, unauthorized access, and physical theft of storage media. It is generally treated as complementary to encryption in transit, which protects data while it moves across networks, and best practice typically applies both.
Encryption at rest refers to the application of cryptographic transformation to persisted data so that stored ciphertext is unreadable without access to the corresponding cryptographic key. It is designed to prevent an attacker who obtains the physical or logical storage medium (disks, SSDs, backup media) from accessing plaintext, since without the key the stored data is unusable. It is distinct from encryption in transit, which secures data as it traverses networks, and the two address different threat surfaces; a comprehensive control posture generally applies both. Encryption at rest is a technical safeguard rather than a regulatory requirement in itself, though it is frequently referenced as a measure that supports data protection and can assist with obligations under regimes such as the GDPR. Implementation details, key management responsibilities, and coverage (for example disk-level versus application-level encryption) vary by platform and deployment, and the specific configuration determines the actual protection achieved; readers should verify particulars against the current documentation of the relevant service or standard.
Why it matters
Data that is stored persists far longer than data in motion, and storage media can be lost, stolen, decommissioned improperly, or accessed through a compromised system. Encryption at rest addresses this exposure by ensuring that, without the corresponding cryptographic key, the stored information is unreadable. According to the evidence reviewed, this control is designed to protect against outcomes such as data breaches, unauthorized access, and the physical theft of disks, solid-state drives, or backup media. It does not eliminate every risk, but it narrows the window in which an attacker who obtains the raw storage can extract usable plaintext.
For compliance purposes, encryption at rest is frequently cited as a technical safeguard that supports data protection obligations rather than being a mandate in its own right. Cloud provider guidance describes it as relevant to regulatory compliance and, in the context of the GDPR, as a measure that can assist with protecting personal data. Readers should note the distinction: encryption at rest is a security control that may help demonstrate that appropriate technical measures are in place, but it is not by itself a regulatory requirement, and its usefulness toward any specific obligation depends on how it is implemented and on the applicable legal regime.
Because encryption at rest and encryption in transit address different threat surfaces, treating one as a substitute for the other leaves a gap. Encryption at rest protects stored data; encryption in transit protects data moving across networks. The sources reviewed consistently describe applying both as best practice, since the actual protection achieved depends on coverage, configuration, and key management rather than on the mere presence of encryption.
Who it's relevant to
Inside Encryption at Rest
Common questions
Answers to the questions practitioners most commonly ask about Encryption at Rest.
