SC.L2-3.13.9[a]: Identify How Your Systems Use Encryption to Protect CUI at Rest

Mapped to NIST 800-171 Requirement: 3.13.9
CMMC Assessment Objective: SC.L2-3.13.9[a]

What This Control Means
You must clearly identify:
• Where CUI is stored across your systems
• How encryption is applied to protect CUI at rest
• Which tools, methods, or services provide that encryption
This includes internal and portable storage, whether on:
• Hard drives
• SSDs
• Mobile devices
• Cloud environments
• Backup systems
• External media like USB drives or removable disks

Why It Matters
If CUI is left unencrypted at rest:
• Physical theft of devices could expose sensitive data
• Insider threats could access stored CUI without detection
• Cloud misconfigurations could lead to public data exposure
• You’ll fail CMMC Level 2 or DFARS compliance assessments
Encrypting CUI at rest ensures protection even if systems are physically compromised.

How to Implement It
1. Inventory Systems Storing CUI
• Laptops, desktops, servers
• Mobile devices (phones, tablets)
• Cloud storage (e.g., AWS S3, Azure Blob Storage)
• Backup and disaster recovery systems
• Removable media
2. Identify Encryption Methods Used Examples:
• BitLocker for Windows laptops and servers
• FileVault for Mac devices
• AWS S3 server-side encryption
• Encrypted external drives
• Database encryption (e.g., TDE for SQL Server)
3. Document Cryptographic Tools and Protocols
• Note:
◦ Encryption algorithms (AES-256, RSA, etc.)
◦ FIPS 140-2 or FIPS 140-3 validation status
◦ Keys management practices (e.g., centralized key management)
4. Include in Your SSP
• Clearly describe where CUI is stored and how it is encrypted at rest

Evidence the Assessor Will Look For
• Inventory of systems with CUI at rest and their encryption status
• SSP entries describing encryption solutions
• Screenshots of encryption settings on devices or storage services
• System or cloud platform configuration files
• Validation that cryptographic modules meet NIST/FIPS standards

Common Gaps
• Systems store CUI at rest but encryption is not applied
• Encryption used but methods not documented
• Personal devices used for storage without encryption enforcement
• Cloud storage configured without encryption defaults

How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Mapping where CUI is stored at rest across your environment
• Documenting encryption tools, protocols, and deployment coverage
• Linking storage assets to cryptographic protections in your SSP
• Verifying encryption compliance against NIST and FIPS standards
• Providing audit-ready evidence of CUI-at-rest protection
With Cuick Trac, encryption of CUI at rest isn’t optional—it’s documented, deployed, and provable.

Final CTA
If your CUI sits still, it should sit encrypted.
Schedule a Cuick Trac demo to identify, document, and protect all your CUI-at-rest with the right cryptography.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.