FedRAMP-SC-28(H): Protect information at rest with FIPS-validated encryption
Vallum evidence mapping for FedRAMP FedRAMP-SC-28(H) — protect information at rest with fips-validated encryption. Documents evidence produced, gaps, and customer responsibilities.
Source Attribution
- Framework
- FedRAMP Rev 5 High
- Control ID
- FedRAMP-SC-28(H)
- Source Organization
- FedRAMP PMO
- Official Source
- FedRAMP Security Controls Baseline ↗
- Control Objective
- Protect information at rest with FIPS-validated encryption
Evidence Vallum Produces
Limited evidence through general operation receipts — full control coverage requires integration with customer's compliance infrastructure
Evidence Vallum Does NOT Produce
FIPS validation certificates, physical security evidence, personnel security records, or infrastructure-level monitoring data
Known Limitations
Vallum provides evidence relevant to this FedRAMP requirement but does not constitute complete control implementation. Full compliance requires complementary controls at infrastructure, organizational, and procedural levels. Evidence covers Vallum-managed operations only and does not extend to customer applications, third-party systems, or physical infrastructure.
Your Responsibilities
Implement FedRAMP-required infrastructure controls, maintain authorization package, engage 3PAO for assessment, and manage POA&M items
External Controls Required
Identity provider, infrastructure security controls, organizational policies and procedures, third-party assessments, and legal/regulatory counsel
Residual Risk
Evidence gaps exist between Vallum-managed operations and full control implementation. Time-of-check to time-of-use windows, infrastructure-level vulnerabilities, and organizational process failures remain outside Vallum's evidence boundary.
Relevant Titan Components
Need a detailed evidence mapping for your specific compliance program?
Request a Control Evidence Mapping