HomeControl Library › 3.13.16
3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.16 — Encrypt CUI at rest

Protect the confidentiality of CUI at rest.

CUI sitting on disks, laptops, and drives should be encrypted.

What it actually means

Protect the confidentiality of CUI at rest — stored on servers, workstations, laptops, and removable media. Full-disk encryption (BitLocker, FileVault) on every device that holds CUI is the standard approach, plus encryption for backups and removable media. Pair it with FIPS-validated cryptography (3.13.11).

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

To fully satisfy this alongside 3.13.11, the at-rest encryption must be FIPS-validated. Most BitLocker / FileVault deployments can run in a FIPS-validated mode.

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library