GlossaryCompliance operations

Encryption

Short answer

Encryption converts readable data into an unreadable format that can only be reversed with the right key. It protects data stored on devices and servers (at rest) and data travelling across networks (in transit), so that it stays confidential even if it is stolen or intercepted.

At rest and in transit

Encryption at rest protects stored data: full disk encryption on laptops (BitLocker, FileVault), encrypted databases, backups and cloud storage. Encryption in transit protects data on the move, mainly through TLS, the protocol behind HTTPS, and VPNs. End to end encryption goes further, so that only the sender and recipient can read the content.

Symmetric and asymmetric

Symmetric algorithms such as AES use the same key to encrypt and decrypt, and are fast enough for large volumes of data. Asymmetric algorithms such as RSA and elliptic curve cryptography use a public and a private key, and are used to exchange keys and create digital signatures. Most systems combine both.

Keys are the weak point

Encryption is only as strong as the management of its keys: where they are stored, who can access them, how they are rotated and how they are recovered. Looking ahead, NIST published its first post quantum cryptography standards in 2024, and organisations are starting to plan the migration.

Where it shows up in compliance

ISO 27001 requires rules on the use of cryptography (Annex A 8.24), and the ENS defines cryptographic measures by category. Under the GDPR, encryption is an example of an appropriate security measure, and if breached personal data was properly encrypted, the company may not need to inform the people affected of a data breach. On laptops, MDM is the usual way to enforce and prove disk encryption.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub