id: "AC-19(05)" title: "Full Device or Container-based Encryption" family: "AC" family_name: "Access Control" sort_id: "ac-19.05" priority: "P1" implementation_level: "organization" parent: "AC-19" enhancement: True
Statement
Employ {{ insert: param, ac-19.05_odp.01 }} to protect the confidentiality and integrity of information on {{ insert: param, ac-19.05_odp.02 }}.
Guidance
Container-based encryption provides a more fine-grained approach to data and information encryption on mobile devices, including encrypting selected data structures such as files, records, or fields.
Assessment Objective
{{ insert: param, ac-19.05_odp.01 }} is employed to protect the confidentiality and integrity of information on {{ insert: param, ac-19.05_odp.02 }}.
Access control policy
procedures addressing access control for mobile devices
system design documentation
system configuration settings and associated documentation
encryption mechanisms and associated configuration documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with access control responsibilities for mobile devices
system/network administrators
organizational personnel with information security responsibilities
Encryption mechanisms protecting confidentiality and integrity of information on mobile devices