Data at rest

Data held in persistent storage, such as disks, databases, backups, removable media and cloud object stores, as distinct from data moving across a network or being processed in memory.

Data at rest is information stored on a persistent medium and not currently moving or being processed: files on a laptop or server, database tables, backup tapes, USB drives, archives and cloud object storage. It is one of the three data states, alongside data in transit and data in use, and the ISC2 outline names all three under objective 2.6. Typical threats are theft or loss of media, misconfigured storage permissions, and recovery of data from discarded media.

Encryption is the main technical control, applied to the whole disk, a file, a database or within the application, commonly with symmetric encryption for bulk data or in hardware through self-encrypting drives. Access control and data loss prevention tools that find where sensitive data sits complete the picture. Full-disk encryption protects a lost or powered-off device, but on a running, unlocked system the operating system decrypts data transparently for any authorised user or process, including malware running as that user. At the end of the media’s life, protection continues through sanitisation, because data remanence outlasts deletion.

Exam relevance: a scenario is likely to describe stored data and ask for the matching control. Candidates are expected to choose encryption and access control for data at rest, and to recognise that disk encryption does not protect data from someone who is already logged on.