Information
Information at rest refers to the state of information when it is located on a secondary storage device (e.g., disk drive and tape drive, when used for backups) within an operating system.
This requirement addresses protection of user-generated data, as well as Ubuntu operating system-specific configuration data. Organizations may choose to employ different mechanisms to achieve confidentiality and integrity protections, as appropriate, in accordance with the security category and/or classification of the information.
Satisfies: SRG-OS-000185-GPOS-00079, SRG-OS-000404-GPOS-00183, SRG-OS-000405-GPOS-00184
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
To encrypt an entire partition, dedicate a partition for encryption in the partition layout.
Note: Encrypting a partition in an already-installed system is more difficult because the existing partitions must be resized and changed.
Item Details
Category: SYSTEM AND COMMUNICATIONS PROTECTION
References: 800-53|SC-28, 800-53|SC-28(1), CAT|II, CCI|CCI-001199, CCI|CCI-002475, CCI|CCI-002476, Rule-ID|SV-219150r958552_rule, STIG-ID|UBTU-18-010003, STIG-Legacy|SV-109629, STIG-Legacy|V-100525, Vuln-ID|V-219150
Control ID: e47e773a52e0642e4c5300b0e3919f79494e9055b14828d7bc52c5b71cfed6f9