SRS-091 AES-256 encryption for data at rest
Identifier​
SRS-091
Software System​
- Authentication Service
Category​
- Security
Description​
To ensure the confidentiality of sensitive information, all data at rest shall be protected using, at a minimum, AES-256 encryption.
This requirement applies to all sensitive data stored by the system, including patient data, system audit logs, and configuration files. This ensures that in the event of a physical or logical breach of the storage medium, the data remains unreadable to unauthorized parties. The implementation within the AWS DocumentDB database must have encryption at rest enabled and properly configured.
Derived from PRS​
PRS-9F2
: Cybersecurity & continuous threat detection