data at rest
termsecuritygovernance & risk
Data sitting in storage rather than moving - and, usually, shorthand for encrypting it there.
Encryption at rest defends against a specific threat: someone obtaining the medium. A stolen disk, a decommissioned array, a copied snapshot. It does nothing against an attacker who has access to the running system, because the system must be able to read its own data. That is why it satisfies a compliance requirement more often than it changes an incident, and why the useful question is where the key lives relative to the data.
Also known as: encryption at rest