Encryption Security Standard
Revision History
| Version No. | Date | Description | |
|---|---|---|---|
| 1.0 | 10/20/2023 | Initial Release | |
| 2.0 | 01/19/2024 | Updated from Encryption Security Policy | |
| 3.0 | 01/22/2026 | Reviewed against NIST 37r2 Risk Management |
1. Introduction
Encryption converts sensitive information or data into an unreadable format called ciphertext, making
it unreadable to unauthorized parties to ensure information remains confidential and secure. This standard provides the guidance to meet the fundamental requirements for encryption which is crucial for maintaining the confidentiality, integrity, and availability of data, aligning WSU System with the National Institute of Standards and Technology’s (NIST) core principles for robust cybersecurity practices.
2. Purpose
Information security standards are created to set processes for areas to facilitate data protection. They also align business goals and strategies with appropriate methods for technically and operationally protecting data. As Information Owners determine their requirements for protecting data, standards define the processes and procedures WSU areas will follow to meet policy requirements.
3. Scope
The control baselines selected for systems are to be commensurate with the potential adverse impact on WSU operations, WSU assets, individuals, other organizations, or the Nation if there is a loss of confidentiality, integrity, or availability. FIPS 199 requires organizations to categorize systems as low impact, moderate-impact, or high-impact for the stated security objectives of confidentiality, integrity, and availability. This standard applies to all Institutional business units, workforce members, and institutional information systems that create, store, use, share, and/or transmit Institutional Data.
4. External Requirements/Drivers
The following Software Development Standard statements are derived from the National Institute of Standards and Technology (NIST) Special Publication 800-53r5 Control Framework.
WSU is required to comply with Federal and/or State laws and regulations related to information security, privacy, and data confidentiality. This standard complies with regulations as defined by:
- FERPA
- HIPPA
- GLBA
5. Effective Dates
January 1st, 2026
6. Instruction
The following Encryption Security Standard statements are applicable all information systems regardless of the Information Owner’s stated Impact (Low, Moderate, or High) in the event Confidentiality, Integrity, or Availability of the information system were to become compromised. See the definition of “Stated Impact”.
7. Standard
Transmission Confidentiality and Integrity SC-8
Control Standard for Moderate, and High Impact Systems:
Protect the [Assignment (one or more): confidentiality, integrity] of transmitted information.
Control Enhancements for Moderate and High Impact Systems:
Cryptographic Protection SC-8(1)
Implement cryptographic mechanisms to [Assignment (one or more): prevent unauthorized disclosure of information, detect changes to information] during transmission.
Cryptographic Key Establishment and Management SC-12
Control Standard for Low, Moderate, and High Impact Systems:
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].
Control Enhancements for High Impact Systems:
Cryptographic Protection SC-8(1)
Maintain availability of information in the event of the loss of cryptographic keys by users.
Cryptographic Protection SC-13
Control Standard for Low, Moderate, and High Impact Systems:
- Determine the [Assignment: organization-defined cryptographic uses].
- Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography for each specified cryptographic use].
Public Key Infrastructure Certificates SC-17
Control Standard for Moderate, and High Impact Systems:
Protect the [Assignment (one or more): confidentiality, integrity] of the following information at rest: [Assignment: organization-defined information at rest].
7.1. Administrative
The Information Owner (e.g., vice president, chancellor, or dean) is responsible for the administration of this standard. The Chief Information Security Officer is responsible for the enforcement of this standard.
8. Review Cycle
This standard shall be reviewed annually.
Appendix A: Acronyms
| Acronym | Definition |
|---|---|
| WSU | Washington State University |
| NIST | National Institute of Standards and Technology |
This content is now available in an accessible HTML format. The original PDF remains available for reference. Encryption Security Standard