Marine Corps data at rest protection is becoming more important as classified information moves onto tactical computers, unmanned systems, sensors, vehicles, servers, and other systems operating beyond established physical security boundaries.
Expeditionary forces increasingly depend on local computing, distributed command and control, sensors, artificial intelligence, and unmanned systems. These capabilities can retain valuable mission information even when disconnected from a network. If a device is lost, abandoned, damaged but recoverable, or captured, the information stored on it may remain accessible unless protection travels with the device.
For Marine Corps programs developing, acquiring, or operating National Security Systems, protecting data at rest requires understanding what information endpoints retain, what happens when physical custody is lost, and how NSA’s Commercial Solutions for Classified Data-at-Rest architecture addresses that threat.
Data at rest is information stored on a physical device rather than information actively moving across a network. For Marine Corps systems, that can include information stored on SSDs, tactical computers, servers, sensors, vehicles, unmanned systems, mission systems, and other edge devices.
A targeting package transmitted to an expeditionary unit is data in transit. Once that information is saved locally, it becomes data at rest.
Across Marine Corps missions, data at rest can reside on:
If a device retains information after power is removed, it can contain data at rest. At the tactical edge, that information can have significant intelligence value.
A captured Marine Corps system can retain mission, intelligence, network, sensor, system, and other operational information depending on its purpose and configuration. A device does not need to contain thousands of classified documents to create potential exposure.
Mission information can include operational plans, objectives, targets, coordinates, routes, waypoints, tasking, and mission histories.
ISR and targeting information can include imagery, video, geospatial information, sensor collections, target information, and intelligence products.
Network and communications information can include configurations, addresses, credentials, communications parameters, and other information associated with tactical networks.
Fires and sensor information can include targeting data, sensor configurations, threat information, and data supporting the integration of sensors and weapons.
System information can include logs, configurations, software, firmware, maintenance information, and diagnostic records.
AI and autonomy information can include trained models, algorithms, sensor fusion data, mission datasets, and software supporting autonomous navigation, recognition, or decision support.
The specific exposure depends on the system, but the design question remains consistent: What information remains on the endpoint if friendly forces no longer possess it?
Data at rest risk grows as more computing and mission information move onto distributed systems operating outside established physical security boundaries. Marine Corps forces have long operated in austere environments, but modern systems can place greater quantities of operationally valuable information on forward endpoints.
Expeditionary Advanced Base Operations and other distributed operating concepts depend on relatively small and mobile forces operating across dispersed locations. Equipment may move rapidly, positions may be temporary, and connectivity may be intermittent.
Those conditions make local computing increasingly important. Sensor information, intelligence, targeting data, and other mission information may need to be processed and retained locally rather than continuously sent to centralized infrastructure.
AI can further increase the value of tactical endpoints because AI-enabled systems may retain models, algorithms, sensor data, mission datasets, and software used for recognition, sensor fusion, decision support, autonomy, or other functions.
Unmanned aircraft, ground vehicles, and maritime platforms create a similar DAR consideration. Whether a system is highly autonomous or remotely operated is secondary from a storage perspective. If it retains sensitive or classified information and can be recovered, its stored information requires appropriate protection.
Physical capture gives another party sustained access to the endpoint itself. Security controls therefore have to account for circumstances in which the system is disconnected from friendly networks and available for physical examination.
A captured tactical computer, sensor, UAS, mission system, or other endpoint can potentially be disassembled. Its storage can be removed. Hardware and firmware interfaces can be examined. Components can be connected to forensic equipment. Similar equipment can be obtained for testing.
This creates a different security assumption from conventional network defense.
Instead of asking only whether an unauthorized user can reach the system remotely, programs also need to ask whether information can be recovered when someone physically possesses the device and has time to examine it.
For expeditionary systems, that question should be considered during architecture and acquisition rather than after fielding.
Commercial encryption can provide strong protection, but encryption strength alone does not define a classified DAR architecture. Programs also need to consider authentication, key protection, startup behavior, implementation, and whether independent protections remain if one security component is compromised.
For example, the use of AES-256 does not answer several important architecture questions:
The relevant question for classified data is therefore broader than the strength of the encryption algorithm. Programs need to determine what controls must be satisfied before stored classified information becomes accessible.
FIPS validation establishes that a cryptographic module has been tested and validated against defined cryptographic module requirements. It does not by itself establish that an entire device or system implements the architecture required to protect classified data at rest.
NIST’s Cryptographic Module Validation Program validates cryptographic modules against FIPS requirements. A product that incorporates a validated module can therefore have an important cryptographic security attribute without the complete endpoint automatically becoming a classified DAR solution.
This distinction matters when evaluating storage.
A program should not stop at the question, “Does this drive use FIPS-validated cryptography?” It should also evaluate how the storage is authenticated, how keys are protected, what happens during startup, and how the component fits into the required DAR architecture.
For National Security Systems containing classified information, those architectural considerations are addressed through applicable NSA requirements rather than by treating FIPS validation as a complete security outcome.
National Security Presidential Memorandum 12, issued June 12, 2026, establishes national policy for the cybersecurity of National Security Systems and identifies the Director of the National Security Agency as the National Manager for National Security Systems.
For Marine Corps organizations developing, acquiring, or operating NSS, this establishes important governance context for cybersecurity and cryptographic protection.
Protecting classified information on an endpoint is therefore not simply a matter of selecting a commercially available encrypted SSD or enabling a general-purpose encryption capability. Programs need to evaluate applicable requirements for the information, system, and mission involved.
NSA’s Commercial Solutions for Classified program provides one mechanism for implementing commercial technologies within defined architectures for classified information.
NSA’s Commercial Solutions for Classified program enables appropriately evaluated commercial technologies to be used within defined architectures for protecting classified information. The CSfC Data-at-Rest Capability Package v5.1.0 provides current requirements and solution designs for protecting stored classified information.
For Marine Corps systems, CSfC DAR shifts the evaluation from whether an individual device is encrypted to whether the complete architecture provides the required independent protections.
A CSfC DAR architecture can use two independent layers:
The encrypted drive and its pre-boot authentication are one layer, not two separate layers. Pre-boot authentication controls access to the encrypted drive before the normal operating system startup process.
The second layer provides independent software full drive encryption. The purpose of the architecture is to avoid placing the protection of classified information entirely on a single security mechanism.
Programs must evaluate the applicable CSfC DAR Capability Package requirements and listed components for the specific solution being implemented.
Authentication matters because encrypted storage has to remain locked until an authorized user satisfies the required access controls. Encryption alone does not answer what causes a device to unlock.
This is particularly important when a tactical system may leave friendly physical control.
Pre-boot authentication operates before the normal operating system startup process and controls access to the encrypted drive. This means the hardware layer is not simply a drive containing encrypted data. It consists of the encrypted drive together with the authentication mechanism controlling access to it.
For classified DAR architectures, programs should evaluate encryption and authentication together rather than treating encryption as a standalone checkbox.
Cryptographic keys determine whether encrypted information can be accessed, which makes their generation, protection, storage, and authorization important parts of the DAR architecture.
An evaluation that looks only at the encryption algorithm can therefore miss critical implementation questions.
Programs should determine how keys are created, where they reside, what controls access to them, and what occurs when a system starts. These questions become especially important when the endpoint may be physically examined outside friendly custody.
The objective is not simply to use strong cryptography. It is to implement the cryptography so that possession of the storage device does not automatically provide access to the information protected by it.
DAR protection must remain effective on the endpoint because expeditionary systems may be captured or lost when no network connection is available. Controls that depend on connectivity cannot be assumed to remain available in that situation.
A captured laptop, UAS, sensor, vehicle system, or tactical server may be disconnected from friendly networks. Remote management services may be unreachable. Communications may be unavailable.
The protections controlling access to stored classified information therefore need to function under the conditions defined by the applicable security architecture even when the system is offline.
For distributed Marine Corps systems, this makes on-device DAR architecture a fundamental design consideration.
Marine Corps programs should evaluate DAR during system design and acquisition by identifying the information stored on each endpoint, the applicable classification and NSS requirements, and the controls that remain effective if physical custody is lost.
Useful architecture questions include:
These questions are easier to address during system architecture and procurement than after equipment has been fielded.
The current public policy and validation framework provides several reference points for evaluating classified DAR.
NSA publishes the CSfC Data-at-Rest Capability Package v5.1.0, dated March 2026, which defines current DAR solution designs and implementation requirements for applicable CSfC solutions.
NIST’s Cryptographic Module Validation Program maintains the validation framework for cryptographic modules under FIPS 140-3. FIPS validation applies to the cryptographic module and should not be interpreted as validation of a complete classified DAR architecture.
NSPM-12, issued June 12, 2026, establishes national cybersecurity policy for National Security Systems and identifies the Director of NSA as the National Manager for NSS.
Programs should verify the current version of applicable policy, capability packages, component listings, and validation records against the relevant public registry when selecting components or designing a solution.
—
Marine Corps systems increasingly store valuable mission information on tactical computers, servers, sensors, unmanned systems, vehicles, and other endpoints operating beyond traditional physical security boundaries. When those systems contain classified information, the security architecture has to account for the possibility that friendly forces may lose physical custody of the equipment.
Encryption is part of that protection, but the architecture also has to address authentication, cryptographic keys, startup behavior, component evaluation, and independent protection layers. FIPS validation establishes important assurance about a cryptographic module, while CSfC DAR addresses how applicable technologies are combined into architectures for protecting classified information.
For Marine Corps programs evaluating classified data at rest protection, use the CSfC DAR Readiness Assessment to identify architecture requirements and areas that may require further review.
Data at rest is information stored on a physical device rather than actively moving across a network. On Marine Corps systems, it can include mission information stored on tactical computers, servers, SSDs, sensors, unmanned systems, vehicles, and edge devices. If information remains stored after connectivity or power is removed, it can constitute data at rest.
Marine Corps systems frequently operate in distributed and expeditionary environments where physical custody cannot always be assumed. Tactical computers, sensors, unmanned systems, and other endpoints can retain classified or sensitive mission information. DAR protection addresses what happens to that stored information if the equipment is lost, abandoned, damaged but recoverable, or captured.
Tactical endpoints can retain operational plans, coordinates, routes, imagery, sensor collections, targeting information, network configurations, system logs, software, maintenance records, and other mission information. AI-enabled systems may also retain models, algorithms, mission datasets, and sensor information. The exact data depends on the system’s mission, configuration, and storage architecture.
AES-256 can be part of a strong cryptographic implementation, but the algorithm alone does not establish a complete classified DAR architecture. Programs also need to evaluate authentication, key protection, startup behavior, implementation, and independent protection layers. The relevant question is how the complete system controls access to classified information when the endpoint is physically available.
FIPS validation applies to a cryptographic module and provides assurance that the module meets defined requirements. It does not by itself establish that an entire storage device or endpoint meets classified DAR architecture requirements. Programs should evaluate FIPS validation in conjunction with the applicable NSA architecture, authentication requirements, and component requirements.
CSfC Data at Rest is part of NSA’s Commercial Solutions for Classified program. The Data-at-Rest Capability Package defines architectures and requirements for using appropriately evaluated commercial technologies to protect stored classified information. The current public DAR Capability Package is v5.1.0, dated March 2026, and programs should verify current requirements before implementation.
A CSfC DAR architecture can use an encrypted drive with pre-boot authentication as the hardware layer and independent software full drive encryption as the second layer. The encrypted drive and pre-boot authentication constitute one layer. They should not be counted as two separate protection layers when describing the architecture.
Pre-boot authentication controls access to the encrypted drive before the normal operating system startup process. This matters when an unauthorized person physically possesses an endpoint because encryption is useful only when access to the encrypted storage remains appropriately controlled. The encrypted drive and its pre-boot authentication together form the hardware protection layer.
DAR requirements affect storage selection, authentication, key management, system architecture, and component integration. Addressing those requirements during acquisition allows programs to evaluate what information the endpoint retains and what protections are required before the system is fielded. Retrofitting those controls later can create additional architecture, integration, and procurement considerations.
Programs should identify the classification of stored information, applicable NSS requirements, required CSfC DAR solution design, authentication controls, key protection, and the consequences of losing physical custody. They should also verify applicable CSfC component listings and cryptographic module validations against current public registries rather than relying on product collateral or previous documentation.
Brett Hansen, Cigent CEO, has 30 years of IT experience. Prior to joining Cigent, held leadership positions with companies providing SaaS data solutions. He was also an executive at Dell for over a decade overseeing Client Software organization including developing and leading Dell Data Security business that provided integrated hardware and software security solutions. Brett started his career with IBM holding leadership positions with various software organizations focusing on IT management, development, and security.