File Level Encryption
PCIComplianceHubLast updated
Encryption applied to individual files, columns or database fields rather than to a whole drive. Because the protection travels with the data and decryption is bound to a specific application or user context, file-level encryption keeps working where full-disk encryption stops: an authenticated user or a compromised process on the host does not automatically obtain the plaintext. This is why PCI DSS treats file, column and field-level encryption as a primary way of rendering a stored primary account number unreadable, while placing restrictions on disk-level encryption used for the same purpose.