Encryption at Rest and in Transit
The use of cryptography to protect data both while it is stored on disks, in databases and in backups, and while it moves across networks, so that intercepted or stolen data cannot be read without the keys.
Encryption in transit protects data moving between clients, servers, services and devices, most commonly with TLS, and also with IPsec or SSH for network and administrative traffic. Encryption at rest protects stored data through full-disk or volume encryption, transparent database encryption, file-level encryption and application-level encryption of sensitive fields. Symmetric algorithms such as AES protect bulk data, while asymmetric cryptography handles key exchange and digital signatures.
Regulations and standards treat encryption as a basic safeguard. GDPR names encryption as an example of an appropriate technical measure, and a breach of properly encrypted data may not require notifying the affected individuals. PCI DSS requires stored account data to be rendered unreadable and cardholder data sent over open, public networks to be encrypted. Customers and auditors routinely ask how data is encrypted in cloud services, backups and portable devices.
Encryption is only as strong as its key management: keys stored next to the data they protect, or accessible to every administrator, offer little protection. Full-disk encryption protects against lost or stolen hardware but not against attackers using a running system with valid access, which is why sensitive fields may also be encrypted at application level. Algorithms and key lengths should follow current guidance, and planning for post-quantum cryptography has begun following NIST's publication of its first post-quantum standards in 2024.
Key points
- In transit usually means TLS; at rest covers disks, databases and backups.
- AES is the standard symmetric algorithm for bulk data.
- Key management determines the real strength of encryption.
- NIST published its first post-quantum cryptography standards in 2024.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Transport Layer Security (TLS)Cybersecurity & Compliance
- Cryptographic Key ManagementCybersecurity & Compliance
- Public Key Infrastructure (PKI)Cybersecurity & Compliance
- General Data Protection Regulation (GDPR)Cybersecurity & Compliance
- Payment Card Industry Data Security Standard (PCI DSS)Cybersecurity & Compliance
- Password HashingCybersecurity & Compliance