{"id":630,"date":"2026-08-12T06:58:46","date_gmt":"2026-08-12T06:58:46","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=630"},"modified":"2026-08-12T06:58:46","modified_gmt":"2026-08-12T06:58:46","slug":"encryption-at-rest","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/","title":{"rendered":"Encryption at Rest vs In Transit: The Difference"},"content":{"rendered":"\n\n<!-- =========================================================================\n     OSTO GLOSSARY: ENCRYPTION AT REST AND IN TRANSIT\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Encryption at rest protects data while it is stored. Encryption in transit protects it while it moves between systems. Most compliance questions ask about both, because they defend against different attacks.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Data protection<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Data at rest is data sitting in a database, a disk, an object store or a backup. Data in transit is data moving across a network. At rest is protected by disk or database encryption with managed keys; in transit is protected by TLS. Neither protects data while an authorised application is using it.<\/p>\n<\/div>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#where\">Where each one applies<\/a><\/li>\n    <li><a href=\"#rest\">Encryption at rest<\/a><\/li>\n    <li><a href=\"#transit\">Encryption in transit<\/a><\/li>\n    <li><a href=\"#frameworks\">What frameworks require<\/a><\/li>\n    <li><a href=\"#osto\">How Osto covers it<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"where\">Where each one applies<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 330\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Encryption in transit covers the network hops between browser, application and database. Encryption at rest covers the database, object storage and backups.\">\n  <defs><marker id=\"enA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#2f6a89\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"52\" width=\"482\" height=\"150\" rx=\"18\" fill=\"#eaf3f9\"\/>\n  <rect x=\"26\" y=\"62\" width=\"150\" height=\"24\" rx=\"12\" fill=\"#2f6a89\"\/>\n  <text x=\"101\" y=\"79\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" letter-spacing=\".8\" fill=\"#ffffff\">IN TRANSIT &#183; TLS<\/text>\n\n  <rect x=\"510\" y=\"52\" width=\"238\" height=\"248\" rx=\"18\" fill=\"#f6eef8\"\/>\n  <rect x=\"524\" y=\"62\" width=\"150\" height=\"24\" rx=\"12\" fill=\"#6b4576\"\/>\n  <text x=\"599\" y=\"79\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" letter-spacing=\".8\" fill=\"#ffffff\">AT REST &#183; STORAGE<\/text>\n\n  <rect x=\"30\" y=\"106\" width=\"130\" height=\"62\" rx=\"12\" fill=\"#ffffff\"\/>\n  <text x=\"95\" y=\"134\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#4a52a8\">Browser<\/text>\n  <text x=\"95\" y=\"153\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">or mobile app<\/text>\n\n  <line x1=\"168\" y1=\"137\" x2=\"240\" y2=\"137\" stroke=\"#2f6a89\" stroke-width=\"2.5\" marker-end=\"url(#enA)\"\/>\n  <text x=\"204\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#2f6a89\">public internet<\/text>\n\n  <rect x=\"250\" y=\"106\" width=\"130\" height=\"62\" rx=\"12\" fill=\"#ffffff\"\/>\n  <text x=\"315\" y=\"134\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3a6f5d\">Your app<\/text>\n  <text x=\"315\" y=\"153\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">reads plaintext<\/text>\n\n  <line x1=\"388\" y1=\"137\" x2=\"470\" y2=\"137\" stroke=\"#2f6a89\" stroke-width=\"2.5\" marker-end=\"url(#enA)\"\/>\n  <text x=\"429\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#2f6a89\">private network<\/text>\n\n  <rect x=\"524\" y=\"106\" width=\"210\" height=\"62\" rx=\"12\" fill=\"#ffffff\"\/>\n  <text x=\"629\" y=\"134\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#6b4576\">Database<\/text>\n  <text x=\"629\" y=\"153\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">encrypted on disk<\/text>\n\n  <rect x=\"524\" y=\"178\" width=\"210\" height=\"52\" rx=\"12\" fill=\"#ffffff\"\/>\n  <text x=\"629\" y=\"200\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#6b4576\">Object storage<\/text>\n  <text x=\"629\" y=\"218\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">files and uploads<\/text>\n\n  <rect x=\"524\" y=\"240\" width=\"210\" height=\"52\" rx=\"12\" fill=\"#ffffff\"\/>\n  <text x=\"629\" y=\"262\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#6b4576\">Backups<\/text>\n  <text x=\"629\" y=\"280\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">the copy most often missed<\/text>\n\n  <rect x=\"12\" y=\"216\" width=\"482\" height=\"84\" rx=\"18\" fill=\"#fdf6f0\"\/>\n  <rect x=\"26\" y=\"226\" width=\"152\" height=\"24\" rx=\"12\" fill=\"#a2603a\"\/>\n  <text x=\"102\" y=\"243\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" letter-spacing=\".8\" fill=\"#ffffff\">IN USE &#183; NEITHER<\/text>\n  <text x=\"30\" y=\"270\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">While your application holds the data in memory it is plaintext.<\/text>\n  <text x=\"30\" y=\"288\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Access control, MFA and DLP are what protect it at that moment.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Blue covers the arrows, where data is moving. Purple covers the boxes on the right, where data is sitting. The third state, in use, is covered by neither.<\/figcaption>\n<\/figure>\n\n<h2 id=\"rest\" class=\"c-sage\">Encryption at rest<\/h2>\n\n<p>At rest encryption defends against someone obtaining the storage itself: a stolen laptop, a copied snapshot, a decommissioned disk, an exposed backup. Cloud providers offer it as a setting, which is why the real work is key management rather than the encryption itself.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Layer<\/th><th>What it protects against<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Full disk or volume<\/strong><\/td><td>Physical theft and access to the underlying storage<\/td><\/tr>\n    <tr><td><strong>Database<\/strong><\/td><td>Copies of database files and snapshots taken outside the application<\/td><\/tr>\n    <tr><td><strong>Field level<\/strong><\/td><td>Exposure of specific sensitive columns even to database operators<\/td><\/tr>\n    <tr><td><strong>Backups<\/strong><\/td><td>The copy most often forgotten, and most often left readable<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The question that follows<\/p>\n  <p>Every <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-readiness-checklist\/\">security questionnaire<\/a> asks who holds the keys and how often they rotate. Encryption where the same platform stores both the data and an unrotated key protects far less than the checkbox suggests.<\/p>\n<\/div>\n\n<h2 id=\"transit\" class=\"c-apri\">Encryption in transit<\/h2>\n\n<p>In transit encryption protects data while it travels. Without it, anyone able to observe the network path, on shared wifi, at an internet provider or inside a compromised network, can read the traffic or alter it.<\/p>\n\n<p>TLS does the work. When a client connects, the two sides agree on encryption keys and verify the server&#8217;s certificate, so the client knows it is talking to the real server and not an impostor. Current practice is TLS 1.2 as the minimum, TLS 1.3 preferred, and SSL along with TLS 1.0 and 1.1 switched off.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Connection<\/th><th>Usually encrypted?<\/th><th>What to check<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Browser to your app<\/strong><\/td><td><span class=\"pill p-yes\">Yes<\/span><\/td><td>HTTPS enforced everywhere, old TLS versions disabled<\/td><\/tr>\n    <tr><td><strong>App to database<\/strong><\/td><td><span class=\"pill p-no\">Often not<\/span><\/td><td>Require TLS on the database connection, not just allow it<\/td><\/tr>\n    <tr><td><strong>Service to service<\/strong><\/td><td><span class=\"pill p-no\">Often not<\/span><\/td><td>Mutual TLS, so both sides prove who they are<\/td><\/tr>\n    <tr><td><strong>App to third-party APIs<\/strong><\/td><td><span class=\"pill p-yes\">Yes<\/span><\/td><td>Certificate validation is actually on, not disabled for convenience<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The gap is nearly always internal. External traffic is encrypted because browsers demand it. Traffic between your own services often is not, on the assumption that a private network is safe, which is exactly the assumption zero trust removes.<\/p>\n\n<h2 id=\"frameworks\" class=\"c-plum\">What frameworks require<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Framework<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>PCI DSS v4.0<\/strong><\/td><td>Requirement 3 for stored account data and Requirement 4 for transmission across open networks.<\/td><\/tr>\n    <tr><td><strong><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>:2022<\/strong><\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A<\/a> 8.24 use of cryptography, supported by a documented key management policy.<\/td><\/tr>\n    <tr><td><strong>HIPAA<\/strong><\/td><td>Encryption is an addressable implementation specification, meaning you either implement it or document why an equivalent measure is used.<\/td><\/tr>\n    <tr><td><strong><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a>, 2023<\/strong><\/td><td>Encryption is named among the reasonable security safeguards expected of a data fiduciary.<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto covers it<\/h2>\n\n<p>Osto manages the transit side directly: SSL and certificate lifecycle management keeps TLS current across your domains, and the WAF terminates and inspects traffic before it reaches origin. On the storage side, cloud posture management flags unencrypted volumes, databases and snapshots across AWS, Azure and GCP, and file access DLP governs who can reach the data once it is decrypted for use.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Prove your encryption story to a buyer<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Certificate lifecycle management, cloud encryption posture and file access controls, with the evidence mapped for you.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">TLS kept current &middot; Unencrypted storage flagged &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is the difference between encryption at rest and in transit?<\/summary>\n  <p>At rest protects stored data on disks, databases, object storage and backups, defending against someone obtaining the storage itself. In transit protects data moving across a network using TLS, defending against interception. Most frameworks require both.<\/p>\n<\/details>\n\n<details>\n  <summary>Is encryption at rest enough on its own?<\/summary>\n  <p>No. Once an authorised application decrypts the data to use it, encryption at rest offers no protection. An attacker with valid application credentials sees plaintext, which is why access control, MFA and data loss prevention sit alongside it.<\/p>\n<\/details>\n\n<details>\n  <summary>What is data in use?<\/summary>\n  <p>The third state: data loaded in memory and being processed. It is not covered by either at rest or in transit encryption. Confidential computing addresses it, but it is rarely required of a startup today.<\/p>\n<\/details>\n\n<details>\n  <summary>Which TLS version should we use?<\/summary>\n  <p>TLS 1.2 as a minimum, with TLS 1.3 preferred, and SSL along with TLS 1.0 and 1.1 disabled. Scanners and security questionnaires both check for the older versions, so leaving them enabled tends to surface quickly.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">Data Loss Prevention<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; SSL Certificate Management &middot; Key Management &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a> &middot; Zero Trust Network Access<\/p>\n\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Encryption at rest protects data while it is stored. Encryption in transit protects it while it moves between systems. Most\u2026<\/p>\n","protected":false},"author":8,"featured_media":631,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[220],"class_list":["post-630","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-encryption-at-rest"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/630","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=630"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/630\/revisions"}],"predecessor-version":[{"id":632,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/630\/revisions\/632"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/631"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}