id: "AC-19(05)" title: "Full Device or Container-based Encryption" family: "AC" family_name: "Access Control" sort_id: "ac-19.05" priority: "P1" implementation_level: "organization" parent: "AC-19" enhancement: True


Statement

Employ {{ insert: param, ac-19.05_odp.01 }} to protect the confidentiality and integrity of information on {{ insert: param, ac-19.05_odp.02 }}.

Guidance

Container-based encryption provides a more fine-grained approach to data and information encryption on mobile devices, including encrypting selected data structures such as files, records, or fields.

Assessment Objective

{{ insert: param, ac-19.05_odp.01 }} is employed to protect the confidentiality and integrity of information on {{ insert: param, ac-19.05_odp.02 }}.

Access control policy

procedures addressing access control for mobile devices

system design documentation

system configuration settings and associated documentation

encryption mechanisms and associated configuration documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with access control responsibilities for mobile devices

system/network administrators

organizational personnel with information security responsibilities

Encryption mechanisms protecting confidentiality and integrity of information on mobile devices