NIST CSF 2.0 · derived mapping target
PR.DS-01Data-at-rest protected
Protect stored data with controls such as encryption and access restrictions, so information remains safe even if storage is lost or stolen.
Mapping at a glance
PR.DS-01Data-at-rest protectedNIST CSF 2.0
PR.DS-01 is covered by 39 Sekit CSF controls. +34 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0091Data classification · PolicyRCF-0092Data classification · ProcessRCF-0093Data classification · TechnicalRCF-0094Encryption at rest · PolicyRCF-0095Encryption at rest · ProcessRCF-0096Encryption at rest · TechnicalRCF-0100Key management · PolicyRCF-0101Key management · ProcessRCF-0102Key management · TechnicalRCF-0103DLP monitoring · PolicyRCF-0104DLP monitoring · ProcessRCF-0105DLP monitoring · TechnicalRCF-0106Data minimization · PolicyRCF-0107Data minimization · ProcessRCF-0108Data minimization · TechnicalRCF-0109Data retention & disposal · PolicyRCF-0110Data retention & disposal · ProcessRCF-0111Data retention & disposal · TechnicalRCF-0112Secrets management · PolicyRCF-0113Secrets management · ProcessRCF-0114Secrets management · TechnicalRCF-0157Removable media control · PolicyRCF-0158Removable media control · ProcessRCF-0159Removable media control · TechnicalRCF-0163Disk encryption · PolicyRCF-0164Disk encryption · ProcessRCF-0165Disk encryption · TechnicalRCF-0208Log protection & retention · PolicyRCF-0209Log protection & retention · ProcessRCF-0210Log protection & retention · TechnicalRCF-0310Media storage & destruction · PolicyRCF-0311Media storage & destruction · ProcessRCF-0312Media storage & destruction · TechnicalRCF-0340KMS & HSM · PolicyRCF-0341KMS & HSM · ProcessRCF-0342KMS & HSM · TechnicalRCF-0364Privacy by design · PolicyRCF-0365Privacy by design · ProcessRCF-0366Privacy by design · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Disk encryption evidence
The proof that laptops and devices handling sensitive data have full-disk encryption (BitLocker, FileVault or similar).
Encryption standards evidence
The proof that sensitive data is encrypted when stored (databases, storage) and when transmitted (encrypted connections).
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves PR.DS-01?”
Also via MCP, free with account