At rest and in transit
Encryption at rest protects stored data: full disk encryption on laptops (BitLocker, FileVault), encrypted databases, backups and cloud storage. Encryption in transit protects data on the move, mainly through TLS, the protocol behind HTTPS, and VPNs. End to end encryption goes further, so that only the sender and recipient can read the content.
Symmetric and asymmetric
Symmetric algorithms such as AES use the same key to encrypt and decrypt, and are fast enough for large volumes of data. Asymmetric algorithms such as RSA and elliptic curve cryptography use a public and a private key, and are used to exchange keys and create digital signatures. Most systems combine both.
Keys are the weak point
Encryption is only as strong as the management of its keys: where they are stored, who can access them, how they are rotated and how they are recovered. Looking ahead, NIST published its first post quantum cryptography standards in 2024, and organisations are starting to plan the migration.
Where it shows up in compliance
ISO 27001 requires rules on the use of cryptography (Annex A 8.24), and the ENS defines cryptographic measures by category. Under the GDPR, encryption is an example of an appropriate security measure, and if breached personal data was properly encrypted, the company may not need to inform the people affected of a data breach. On laptops, MDM is the usual way to enforce and prove disk encryption.




