Migration Planning / Data-at-Rest Strategy

What this is for: Phase 5 Activity 5.6 — per-store data-at-rest decision (re-encrypt under PQC keys, PQC key-wrap, crypto-shred, delete, or accept & monitor), recorded back into the CBOM.

What a good answer looks like: Retention drives the order. Data that stays secret for ten years is the harvest-now target; data that expires next quarter is not.

Worked example: Keep the four seeded stores, 'Customer PII database' on High with 'Re-encrypt with fresh AES-256 DEK (PQC-wrapped KEK)' and 'Backups & archives' on 'Re-wrap existing DEK under PQC KEK': the export is a store / sensitivity / strategy table.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
For each data store, set the sensitivity and choose re-encrypt, re-wrap, crypto-shred, delete or accept and monitor: retention drives the order, because data that stays secret for ten years is the harvest-now target.
GRC / Risk & Compliance
Enter each store with its retention note and the decision taken: the export records the per-store data-at-rest disposition back into the CBOM, which is the evidence of Phase 5 activity 5.6.

Data-at-Rest Strategy

Phase 5 — Activity 5.6. Decide a per-data-store strategy: re-wrap the AES-256 key under an ML-KEM (PQC) KEK, write a fresh AES-256 DEK with a PQC-wrapped KEK, crypto-shred, delete, or accept & monitor. Bulk data stays AES-256 (Grover only halves it to ~128-bit — still quantum-safe per NIST IR 8547, currently an Initial Public Draft, not yet finalized); PQC protects the key, not the cipher.

Data stores · 4 stores

Give backups & archives their own line — cold copies are not covered by the live-store decision and often outlive it.

Confidentiality horizon / sensitivity

Strategy choice should track how long this data must stay confidential, its volume, and its exfiltration exposure — not just what's convenient.

Strategy

Delete and Crypto-shred should be carried out per NIST SP 800-88 (Guidelines for Media Sanitization) so destruction is verifiable.

Confidentiality horizon / sensitivity

Strategy choice should track how long this data must stay confidential, its volume, and its exfiltration exposure — not just what's convenient.

Strategy

Delete and Crypto-shred should be carried out per NIST SP 800-88 (Guidelines for Media Sanitization) so destruction is verifiable.

Confidentiality horizon / sensitivity

Strategy choice should track how long this data must stay confidential, its volume, and its exfiltration exposure — not just what's convenient.

Strategy

Delete and Crypto-shred should be carried out per NIST SP 800-88 (Guidelines for Media Sanitization) so destruction is verifiable.

Confidentiality horizon / sensitivity

Strategy choice should track how long this data must stay confidential, its volume, and its exfiltration exposure — not just what's convenient.

Strategy

Delete and Crypto-shred should be carried out per NIST SP 800-88 (Guidelines for Media Sanitization) so destruction is verifiable.

Data-at-Rest Strategy — Export

Save this strategy to your Command Center, or export as markdown / PDF / Word. Record the chosen strategy per store in the CBOM (Applied Quantum Phase 5 Activity 5.6).

Try it

Which stores does the tool say to treat first?

Next step

Next in Migration Planning: Migration Verification & Closure

Migration Verification & Closure is the next Migration Planning tool in the Command Center.