Disk Encryption

Disk encryption three states and audit evidence explained

Disk encryption protects a laptop that has been lost or stolen. It does almost nothing for a laptop that is switched on and logged in, and confusing the two is how it ends up carrying more weight than it can hold.

  • Glossary
  • Endpoint

The short answer

Disk encryption, often called full disk encryption or FDE, encrypts an entire drive so its contents are unreadable without the key. On a managed fleet it is enforced centrally through BitLocker on Windows and FileVault on macOS, with recovery keys escrowed by the organisation. Its threat model is physical: a device that leaves the building in someone else’s hands.

That narrow scope is the whole point of the control, and also the source of every misunderstanding about it.

Disk encryption in three states

Whether the control is doing anything depends entirely on the state of the machine at the moment something goes wrong.

Powered off Volume key is not in memory Protected Locked screen Key is in memory, screen is locked Partly protected Unlocked and in use Files decrypt transparently Not protected Malware, a logged-in user and a stolen session all operate in the third state. Which is why screen lock timeout is part of the same control, not a separate nicety.

Encryption without screen lock is half a control

A stolen laptop is far more often taken from a desk or a cafe table than from a locked cupboard, which means it is frequently taken awake. Disk encryption only engages once the machine reaches a powered-off or locked state, so a short screen lock timeout and a requirement for credentials on wake are what actually make the control operate in the real theft scenario. Auditors increasingly sample both together for this reason.

Disk encryption and encryption at rest

Related, frequently conflated on questionnaires, and answering one when asked about the other is a common way to stall a review.

Disk encryptionEncryption at rest
What it coversThe whole volume on a physical machineData in databases, object storage, backups and snapshots
Threat it addressesPhysical loss or theft of the deviceUnauthorised access to stored data in infrastructure
Where it runsLaptops, desktops, serversCloud services and managed storage
Who enforces itThe endpoint agent and OSCloud provider configuration and application design
Typical evidenceFleet coverage report showing encryption on per deviceConfiguration state for each store, plus key handling

A buyer asking whether you encrypt customer data at rest is asking about your infrastructure. A buyer asking whether employee laptops are encrypted is asking about disk encryption. Both appear on most security questionnaires, usually in different sections.

What auditors actually check

What they ask forWhy it fails
Fleet coverage reportA handful of devices show as unencrypted, usually contractor or older machines nobody enrolled
Recovery key escrowKeys sit with individual users rather than the organisation, so the company cannot recover its own data
Enforcement mechanismEncryption was enabled by hand at setup and there is nothing preventing a user turning it off
Screen lock policySet to a length that means a stolen machine is almost always taken unlocked
Exception listExceptions exist with no owner, no expiry and no record of who approved them
Decommissioning evidenceNo record of what happened to drives in devices that left the fleet

Coverage is the recurring theme. Enabling disk encryption is trivial; proving that every in-scope device has it on, that nobody can switch it off, and that the organisation holds the recovery keys, is the part that takes work and the part that gets sampled.

Where frameworks require disk encryption

FrameworkWhat it expects
PCI DSSCardholder data rendered unreadable wherever stored, with documented key management
ISO 27001Annex A controls for use of cryptography, storage media and endpoint devices
SOC 2Protection of data on endpoints, evidenced as operating throughout the observation window
HIPAAEncryption as an addressable specification, meaning implement it or document why not
DPDP ActReasonable security safeguards over personal data, including on the devices holding it
RBI and SEBI frameworksEncryption of sensitive data on endpoints for regulated entities, with central enforcement

Several breach notification regimes also treat encryption as a mitigating factor. A lost device that was encrypted, with keys held separately, is a materially different disclosure conversation from a lost device that was not.

How Osto handles disk encryption

Disk encryption is enforced from the same agent as the rest of the endpoint stack, alongside antimalware and application control, device control and screen lock policy. Because screen lock sits in the same policy set, the gap described above closes as one configuration rather than two teams agreeing on a standard.

Coverage reporting is the output that matters. Every enrolled device shows encryption state in one view, so the answer to an auditor or a buyer is a report rather than a spreadsheet somebody maintains by hand. That evidence maps into SOC 2, ISO 27001 and PCI DSS from one control set and feeds the GRC evidence base directly.

Platform walkthrough

Coverage you can hand to an auditor

Encryption and screen lock enforced from the same agent that runs antimalware, device control and file access policy, with fleet coverage in one view. One owner, one dashboard.

Book a demo

Fleet coverage reporting · 200+ frameworks mapped · One platform, everything

Frequently asked questions

What is disk encryption?

Encryption of an entire drive so its contents are unreadable without the key. It is implemented through BitLocker on Windows and FileVault on macOS, and on a managed fleet it is enforced centrally with recovery keys held by the organisation rather than the user.

Does disk encryption protect against malware or ransomware?

No. On a running, logged-in machine files decrypt transparently, so software with access to the operating system sees plaintext. Disk encryption addresses physical loss and theft. Malware is the job of endpoint protection and EDR.

What is the difference between disk encryption and encryption at rest?

Disk encryption covers the whole volume on a physical machine and addresses device theft. Encryption at rest covers data held in databases, object storage and backups, and addresses unauthorised access within infrastructure. Questionnaires ask about both, usually in different sections.

Do we need it if the laptop has a strong password?

Yes. Without encryption, the drive can be removed and read on another machine, where the original password is irrelevant. The password protects the running session. Encryption protects the storage itself.

What evidence do auditors want?

A fleet coverage report showing encryption state per device, proof that it is centrally enforced rather than manually enabled, evidence that recovery keys are escrowed by the organisation, screen lock policy, and an exception list with owners and expiry dates.