A Practical Guide to Encrypting Sensitive Data
Protecting data at rest and in transit with encryption, and managing the keys that make it work.
What is at stake
Encryption limits breach impact, but poor key management makes it decorative rather than protective.
The playbook
- Use TLS everywhere, including internal traffic
- Encrypt sensitive fields as well as whole disks
- Store keys in a managed key service
- Plan key rotation before you need it
- Limit who can access decryption keys
Where it goes wrong
Avoid:
- Keys stored beside encrypted data
- Custom cryptography
- Encryption with no rotation plan
- Assuming disk encryption covers application risks
The numbers behind it
| Measure | Figure |
|---|---|
| In transit | TLS protects data moving between systems |
| At rest | database and disk encryption protect stored data |
| Key management | keys must be stored separately from the data |
| Rotation | keys should be rotatable without data loss |
Getting outside help
When to hand it over: Bring in help when applications hold sensitive personal data.
Where this comes from
- OWASP — Cryptographic Storage Cheat Sheet
- National Institute of Standards and Technology — Cryptographic standards
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.