‹ Back to Act

Risk / detail

ACME Corp

Encrypt the legacy datastore at rest and rotate keys to the managed KMS

Score impact
+6 posture
Loss avoided (ALE)
$640K
Effort
~2 weeks · Data Engineering
Frameworks satisfied
3

Plan

4 steps
  1. Snapshot + classify records in the legacy datastore
  2. Enable encryption at rest; migrate keys to managed KMS
  3. Rotate keys and verify cipher coverage
  4. Attach KMS config evidence → HIPAA/GDPR/NIST

Closes

critical
Unencrypted patient data in a legacy datastore
View the exposure →

Satisfies — one fix, many frameworks

Because every control maps through the CSF hub, completing this single action posts evidence to all 3 frameworks at once — no duplicate work.