Data Protection

Encrypt Data at Rest and in Transit

Protect sensitive data from unauthorized access through comprehensive encryption controls.

Content review: 2026-09-22 · Estimated effort: Medium

Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.

Before you start

Before starting: identify sensitive data and owners. Verify backups and authorized recovery-key access before changing disk or storage encryption.

Put it into practice

  1. Check encryption features included with your operating systems and cloud services. Pilot on a supported device, following vendor instructions and licensing requirements.
  2. Verify recovery keys are securely stored and retrievable by authorized staff. Never keep the only recovery key solely on the device it unlocks.
  3. Expand coverage to sensitive storage and backups. Check provider encryption settings and key ownership before changing keys or access policies.
  4. Use supported HTTPS/TLS configurations and valid certificates with renewal monitoring. Test service dependencies before disabling obsolete protocols. Review sharing permissions too: encryption does not prevent authorized-account misuse.
  5. Verify: inspect actual encryption status, test authorized key retrieval without exposing keys, and confirm certificate validity and service connectivity after changes.

Make a start

Tools and templates

Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.

Start without another software subscription

Check whether the existing Windows device supports BitLocker or Device Encryption and verify recovery access before changing settings.

Where this stops: Where neither is available, record the gap and assess a supported upgrade or suitable device. File-only encryption is not an equivalent substitute for whole-device protection; central management may need separate licensing.

See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.

Windows BitLocker and Device Encryption

Edition- and hardware-dependent Windows features; check eligibility

Check encryption status and confirm authorized recovery-key retrieval before enabling or changing encryption. Follow the Microsoft instructions for your device and edition.

Limits: Full BitLocker management is not in every Windows edition; Device Encryption depends on hardware and configuration. Intune management is separately licensed. Disk encryption does not prevent an authorized signed-in user from copying files.

Your information: Recovery material may be backed up to an account or directory according to setup. Confirm the approved location and access; never put keys in the worksheet.

Official instructions: Windows BitLocker and Device Encryption ↗

Download a working template

Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.

Fictional worked example

Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.

A team checks a business laptop before an employee takes it off-site.

Use the Encryption and recovery-access review template.

What to enter before testing

Asset or service reference
EXAMPLE-LAPTOP-03
Actual encryption state
Not verified
Recovery storage reference - NEVER KEY
Restricted location reference only
Authorized recovery access checked
Not tested

How to verify

With permission, inspect actual encryption status and protection state, confirm edition and capability, and check that authorized staff can retrieve the matching recovery material securely. Confirm backup prerequisites before changing settings. Do not place the recovery key in the worksheet.

If the result is unexpected

If protection is suspended, encryption incomplete or recovery access unavailable, record the gap and involve the device owner before rollout. Do not force a recovery lockout to test access. Disk encryption alone does not verify encryption for email, network traffic or cloud services.

Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.

Sources and review approach

Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.

  • NIST CSF 2.0: PR.DS-01, PR.DS-02: encryption contributes to, but does not fully satisfy, data protection
How this guidance is prepared