Run a Data-at-Rest Threat Model
Build a simple threat model for encryption at rest across devices, files, backups, and logs.
Candidate interview notes appear in the app database, weekly backups, recruiter laptop exports, and a search index. Storage threat model: resting place, exposure scenario, matching control, residual risk. The common shortcut is to say the database is encrypted and ignore exports, logs, indexes, and local copies. List resting places Database, backups, search index, recruiter exports, local notes, and logs. Encryption at rest only works where it is applied. Unknown copies are unreviewed risk. Name exposure Lost laptop, copied backup, overbroad search access, and retained local exports. Each storage location has a different failure mode, so one control rarely covers them…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in