Encryption Security Standard

Revision History

Version No.DateDescription
1.010/20/2023Initial Release
2.001/19/2024Updated from Encryption Security Policy
3.001/22/2026Reviewed against NIST 37r2 Risk Management
Revision Table

1. Introduction

Encryption converts sensitive information or data into an unreadable format called ciphertext, making
it unreadable to unauthorized parties to ensure information remains confidential and secure. This standard provides the guidance to meet the fundamental requirements for encryption which is crucial for maintaining the confidentiality, integrity, and availability of data, aligning WSU System with the National Institute of Standards and Technology’s (NIST) core principles for robust cybersecurity practices.

2. Purpose

Information security standards are created to set processes for areas to facilitate data protection. They also align business goals and strategies with appropriate methods for technically and operationally protecting data. As Information Owners determine their requirements for protecting data, standards define the processes and procedures WSU areas will follow to meet policy requirements.

3. Scope

The control baselines selected for systems are to be commensurate with the potential adverse impact on WSU operations, WSU assets, individuals, other organizations, or the Nation if there is a loss of confidentiality, integrity, or availability. FIPS 199 requires organizations to categorize systems as low impact, moderate-impact, or high-impact for the stated security objectives of confidentiality, integrity, and availability. This standard applies to all Institutional business units, workforce members, and institutional information systems that create, store, use, share, and/or transmit Institutional Data.

4. External Requirements/Drivers

The following Software Development Standard statements are derived from the National Institute of Standards and Technology (NIST) Special Publication 800-53r5 Control Framework.

WSU is required to comply with Federal and/or State laws and regulations related to information security, privacy, and data confidentiality. This standard complies with regulations as defined by:

  • FERPA
  • HIPPA
  • GLBA

5. Effective Dates

January 1st, 2026

6. Instruction

The following Encryption Security Standard statements are applicable all information systems regardless of the Information Owner’s stated Impact (Low, Moderate, or High) in the event Confidentiality, Integrity, or Availability of the information system were to become compromised. See the definition of “Stated Impact”.

7. Standard

Transmission Confidentiality and Integrity SC-8

Control Standard for Moderate, and High Impact Systems:

Protect the [Assignment (one or more): confidentiality, integrity] of transmitted information.

Control Enhancements for Moderate and High Impact Systems:

Cryptographic Protection SC-8(1)

Implement cryptographic mechanisms to [Assignment (one or more): prevent unauthorized disclosure of information, detect changes to information] during transmission.

Cryptographic Key Establishment and Management SC-12

Control Standard for Low, Moderate, and High Impact Systems:

Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].

Control Enhancements for High Impact Systems:

Cryptographic Protection SC-8(1)

Maintain availability of information in the event of the loss of cryptographic keys by users.

Cryptographic Protection SC-13

Control Standard for Low, Moderate, and High Impact Systems:

  • Determine the [Assignment: organization-defined cryptographic uses].
  • Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography for each specified cryptographic use].

Public Key Infrastructure Certificates SC-17

Control Standard for Moderate, and High Impact Systems:

Protect the [Assignment (one or more): confidentiality, integrity] of the following information at rest: [Assignment: organization-defined information at rest].

7.1. Administrative

The Information Owner (e.g., vice president, chancellor, or dean) is responsible for the administration of this standard. The Chief Information Security Officer is responsible for the enforcement of this standard.

8. Review Cycle

This standard shall be reviewed annually.

Appendix A: Acronyms

AcronymDefinition
WSUWashington State University
NISTNational Institute of Standards and Technology
Acronyms Table
Note:

This content is now available in an accessible HTML format. The original PDF remains available for reference. Encryption Security Standard