{"id":1154,"date":"2026-09-10T13:13:16","date_gmt":"2026-09-10T13:13:16","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1154"},"modified":"2026-09-10T13:13:16","modified_gmt":"2026-09-10T13:13:16","slug":"disk-encryption","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/disk-encryption\/","title":{"rendered":"Disk Encryption"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: DISK ENCRYPTION\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Disk encryption protects a laptop that has been lost or stolen. It does almost nothing for a laptop that is switched on and logged in, and confusing the two is how it ends up carrying more weight than it can hold.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Endpoint<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Disk encryption, often called full disk encryption or FDE, encrypts an entire drive so its contents are unreadable without the key. On a managed fleet it is enforced centrally through BitLocker on Windows and FileVault on macOS, with recovery keys escrowed by the organisation. Its threat model is physical: a device that leaves the building in someone else&#8217;s hands.<\/p>\n<\/div>\n\n<p>That narrow scope is the whole point of the control, and also the source of every misunderstanding about it.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#states\">Disk encryption in three states<\/a><\/li>\n    <li><a href=\"#at-rest\">Disk encryption and encryption at rest<\/a><\/li>\n    <li><a href=\"#auditors\">What auditors actually check<\/a><\/li>\n    <li><a href=\"#frameworks\">Where frameworks require disk encryption<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles disk encryption<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"states\">Disk encryption in three states<\/h2>\n\n<p>Whether the control is doing anything depends entirely on the state of the machine at the moment something goes wrong.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 190\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Three states of an encrypted disk: powered off, locked and unlocked, and what each protects against.\">\n  <rect x=\"12\" y=\"24\" width=\"238\" height=\"96\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"131\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Powered off<\/text>\n  <text x=\"131\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">Volume key is not in memory<\/text>\n  <text x=\"131\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#8fe3bd\">Protected<\/text>\n\n  <rect x=\"260\" y=\"24\" width=\"238\" height=\"96\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"379\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Locked screen<\/text>\n  <text x=\"379\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Key is in memory, screen is locked<\/text>\n  <text x=\"379\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#a2603a\">Partly protected<\/text>\n\n  <rect x=\"508\" y=\"24\" width=\"240\" height=\"96\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"628\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Unlocked and in use<\/text>\n  <text x=\"628\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Files decrypt transparently<\/text>\n  <text x=\"628\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#b4413a\">Not protected<\/text>\n\n  <rect x=\"12\" y=\"132\" width=\"736\" height=\"44\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"152\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Malware, a logged-in user and a stolen session all operate in the third state.<\/text>\n  <text x=\"380\" y=\"168\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3a6f5d\">Which is why screen lock timeout is part of the same control, not a separate nicety.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<div class=\"callout\">\n  <p class=\"k\">Encryption without screen lock is half a control<\/p>\n  <p>A stolen laptop is far more often taken from a desk or a cafe table than from a locked cupboard, which means it is frequently taken awake. Disk encryption only engages once the machine reaches a powered-off or locked state, so a short screen lock timeout and a requirement for credentials on wake are what actually make the control operate in the real theft scenario. Auditors increasingly sample both together for this reason.<\/p>\n<\/div>\n\n<h2 id=\"at-rest\" class=\"c-sage\">Disk encryption and encryption at rest<\/h2>\n\n<p>Related, frequently conflated on questionnaires, and answering one when asked about the other is a common way to stall a review.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>Disk encryption<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at rest<\/a><\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>What it covers<\/td><td>The whole volume on a physical machine<\/td><td>Data in databases, object storage, backups and snapshots<\/td><\/tr>\n    <tr><td>Threat it addresses<\/td><td>Physical loss or theft of the device<\/td><td>Unauthorised access to stored data in infrastructure<\/td><\/tr>\n    <tr><td>Where it runs<\/td><td>Laptops, desktops, servers<\/td><td>Cloud services and managed storage<\/td><\/tr>\n    <tr><td>Who enforces it<\/td><td>The endpoint agent and OS<\/td><td>Cloud provider configuration and application design<\/td><\/tr>\n    <tr><td>Typical evidence<\/td><td>Fleet coverage report showing encryption on per device<\/td><td>Configuration state for each store, plus key handling<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>A buyer asking whether you encrypt customer data at rest is asking about your infrastructure. A buyer asking whether employee laptops are encrypted is asking about disk encryption. Both appear on most <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">security questionnaires<\/a>, usually in different sections.<\/p>\n\n<h2 id=\"auditors\" class=\"c-plum\">What auditors actually check<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>What they ask for<\/th><th>Why it fails<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Fleet coverage report<\/td><td>A handful of devices show as unencrypted, usually contractor or older machines nobody enrolled<\/td><\/tr>\n    <tr><td>Recovery key escrow<\/td><td>Keys sit with individual users rather than the organisation, so the company cannot recover its own data<\/td><\/tr>\n    <tr><td>Enforcement mechanism<\/td><td>Encryption was enabled by hand at setup and there is nothing preventing a user turning it off<\/td><\/tr>\n    <tr><td>Screen lock policy<\/td><td>Set to a length that means a stolen machine is almost always taken unlocked<\/td><\/tr>\n    <tr><td>Exception list<\/td><td>Exceptions exist with no owner, no expiry and no record of who approved them<\/td><\/tr>\n    <tr><td>Decommissioning evidence<\/td><td>No record of what happened to drives in devices that left the fleet<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Coverage is the recurring theme. Enabling disk encryption is trivial; proving that every in-scope device has it on, that nobody can switch it off, and that the organisation holds the recovery keys, is the part that takes work and the part that gets sampled.<\/p>\n\n<h2 id=\"frameworks\" class=\"c-sky\">Where frameworks require disk encryption<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Framework<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a><\/td><td>Cardholder data rendered unreadable wherever stored, with documented key management<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A controls<\/a> for use of cryptography, storage media and endpoint devices<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/td><td>Protection of data on endpoints, evidenced as operating throughout the observation window<\/td><\/tr>\n    <tr><td>HIPAA<\/td><td>Encryption as an addressable specification, meaning implement it or document why not<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td>Reasonable security safeguards over personal data, including on the devices holding it<\/td><\/tr>\n    <tr><td>RBI and SEBI frameworks<\/td><td>Encryption of sensitive data on endpoints for regulated entities, with central enforcement<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Several breach notification regimes also treat encryption as a mitigating factor. A lost device that was encrypted, with keys held separately, is a materially different disclosure conversation from a lost device that was not.<\/p>\n\n<h2 id=\"osto\">How Osto handles disk encryption<\/h2>\n\n<p>Disk encryption is enforced from the same agent as the rest of the endpoint stack, alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">antimalware and application control<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">device control<\/a> and screen lock policy. Because screen lock sits in the same policy set, the gap described above closes as one configuration rather than two teams agreeing on a standard.<\/p>\n\n<p>Coverage reporting is the output that matters. Every enrolled device shows encryption state in one view, so the answer to an auditor or a buyer is a report rather than a spreadsheet somebody maintains by hand. That evidence maps into <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> from one control set and feeds the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> evidence base directly.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Coverage you can hand to an auditor<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Encryption and screen lock enforced from the same agent that runs antimalware, device control and file access policy, with fleet coverage in one view. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Fleet coverage reporting &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is disk encryption?<\/summary>\n  <p>Encryption of an entire drive so its contents are unreadable without the key. It is implemented through BitLocker on Windows and FileVault on macOS, and on a managed fleet it is enforced centrally with recovery keys held by the organisation rather than the user.<\/p>\n<\/details>\n\n<details>\n  <summary>Does disk encryption protect against malware or ransomware?<\/summary>\n  <p>No. On a running, logged-in machine files decrypt transparently, so software with access to the operating system sees plaintext. Disk encryption addresses physical loss and theft. Malware is the job of <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">endpoint protection<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a>.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between disk encryption and encryption at rest?<\/summary>\n  <p>Disk encryption covers the whole volume on a physical machine and addresses device theft. Encryption at rest covers data held in databases, object storage and backups, and addresses unauthorised access within infrastructure. Questionnaires ask about both, usually in different sections.<\/p>\n<\/details>\n\n<details>\n  <summary>Do we need it if the laptop has a strong password?<\/summary>\n  <p>Yes. Without encryption, the drive can be removed and read on another machine, where the original password is irrelevant. The password protects the running session. Encryption protects the storage itself.<\/p>\n<\/details>\n\n<details>\n  <summary>What evidence do auditors want?<\/summary>\n  <p>A fleet coverage report showing encryption state per device, proof that it is centrally enforced rather than manually enabled, evidence that recovery keys are escrowed by the organisation, screen lock policy, and an exception list with owners and expiry dates.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at Rest<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">Device Control<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">EPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mdm\/\">MDM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">DLP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Disk encryption protects a laptop that has been lost or stolen. It does almost nothing for a laptop that is\u2026<\/p>\n","protected":false},"author":8,"featured_media":1155,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[557,559,558,556],"class_list":["post-1154","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-disk-encryption","tag-disk-encryption-vs-encryption-at-rest","tag-fde","tag-full-disk-encryption"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1154","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1154"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1154\/revisions"}],"predecessor-version":[{"id":1156,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1154\/revisions\/1156"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1155"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}