Encryption
Encryption is a process that converts readable data into a scrambled form so that only someone with the correct key can read it. It helps protect information from being viewed, stolen, or altered by unauthorized parties. In a governance and compliance context, encryption is commonly used as a control to safeguard sensitive or regulated data.
Encryption is the cryptographic transformation of plaintext data into ciphertext to conceal its original meaning and prevent it from being known or used by unauthorized parties. Only holders of the appropriate key can reverse the transformation (decrypt) to recover the original data. As a security control, encryption supports data confidentiality and integrity objectives; the strength and adequacy of a given implementation depend on the algorithms, key management practices, and applicable regulatory or framework requirements, which vary by jurisdiction, sector, and entity. This entry describes the concept generally and does not prescribe any specific technical standard as mandatory.
Why it matters
Encryption is one of the most widely relied-upon technical controls for protecting sensitive and regulated data. By converting readable information into ciphertext that only a holder of the correct key can reverse, it directly supports confidentiality objectives and can help preserve the integrity of data against unauthorized alteration. For governance, risk, and compliance professionals, encryption is often central to how an organization demonstrates that it has taken reasonable steps to safeguard information it holds, whether that data is at rest in storage systems or in transit across networks.
Because many data protection regimes and security frameworks treat the protection of sensitive data as a core expectation, encryption frequently appears as a candidate control in risk assessments and control frameworks. Its presence or absence can influence the residual risk associated with a data asset, and the adequacy of a given implementation depends on factors such as the algorithms used and how keys are managed rather than on the mere fact that encryption is deployed. Whether encryption is legally required, expected as good practice, or left to management's judgment varies by jurisdiction, sector, and entity type, so professionals should confirm the specific obligations that apply to their organization.
Encryption is not a complete solution on its own. It reduces certain risks but shifts attention to key management, access governance, and the operating effectiveness of the surrounding controls. Treating encryption as a single checkbox rather than as a control whose design and operation must be tested can create a false sense of assurance. This entry is educational and general in nature and does not constitute legal, audit, or compliance advice.
Who it's relevant to
Inside Encryption
Common questions
Answers to the questions practitioners most commonly ask about Encryption.