Cyber Resilience

CWE · MITRE source

CWE-311Missing Encryption of Sensitive Data

Abstraction: Class · CVEs in our corpus: 515

The product does not encrypt sensitive or critical information before storage or transmission.

Last updated: 21 August 2026 20:21 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: full · 19 mapping(s) from 9 framework(s): CAPEC 9 (partial) · CSF 2.0 2 (mostly) · ATT&CK 2 (partial) · STIG windows server 2019 1 (full) · STIG oracle linux 8 1 (mostly) · STIG oracle linux 9 1 (mostly) · STIG rhel 8 1 (mostly) · STIG rhel 9 1 (mostly) · STIG windows server 2016 1 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A06:2025 Insecure Design.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • CM-13 Data Action Mapping
  • CM-6 Configuration Settings
  • PM-13 Security and Privacy Workforce
  • PM-17 Protecting Controlled Unclassified Information on External Systems
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 7 hardening rules · 7 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (12)AI-assisted

Control Title Family Why it addresses this CWE
CM-13Data Action MappingCMThe map highlights data actions that involve sensitive data, enabling identification of missing encryption requirements.
CM-6Configuration SettingsCMSettings can require encryption of sensitive data, preventing missing encryption weaknesses.
PM-13Security and Privacy WorkforcePMPrivacy and security curricula stress encryption requirements, reducing missing encryption of sensitive data.
PM-17Protecting Controlled Unclassified Information on External SystemsPMRequires encryption and similar controls for CUI processed or stored externally, preventing missing encryption of sensitive data.
RA-5Vulnerability Monitoring and ScanningRAMonitoring detects missing encryption of sensitive data in storage or transit configurations.
RA-8Privacy Impact AssessmentsRAPrivacy assessments routinely identify the need for encryption of PII, directly lowering the impact of missing encryption weaknesses.
SA-3System Development Life CycleSAPrivacy and security considerations mandated across the SDLC make identification and protection of sensitive data (including encryption decisions) a required activity rather than an afterthought.
SA-9External System ServicesSAPrivacy and security requirements placed on external providers, together with monitoring, tangibly reduce missing encryption of sensitive data processed or stored by those services.
AT-3Role-based TrainingATPrivacy and security training stresses encryption of sensitive data, reducing missing encryption weaknesses.
CA-3Information ExchangeCAExchange agreements must document security requirements, which would include encryption to protect sensitive data in transit.
PL-8Security and Privacy ArchitecturesPLArchitectures must describe confidentiality protections, which includes mandating encryption for sensitive data in transit and at rest.
SC-13Cryptographic ProtectionSCMandates encryption for specified data uses, directly preventing missing encryption of sensitive information.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-279448.69.80.22162026-03-05
CVE-2026-34486 KEV 8.57.50.82932026-04-09
CVE-2019-11367 7.89.80.02822019-06-03
CVE-2018-10698 7.79.80.02342019-06-07
CVE-2017-3198 7.69.80.01602018-07-09
CVE-2017-9854 7.59.80.01132017-08-05
CVE-2018-17915 7.59.80.01102018-10-10
CVE-2018-16879 7.59.80.01112019-01-03
CVE-2018-10612 7.59.80.01272019-01-29
CVE-2019-6526 7.59.80.01002019-04-15
CVE-2019-11523 7.59.80.01212019-06-06
CVE-2019-12924 7.59.80.00902019-07-08
CVE-2019-14480 7.59.80.01122020-12-16
CVE-2020-15331 7.59.80.00892022-09-29
CVE-2017-7406 7.49.80.00692017-07-07
CVE-2018-7498 7.49.80.00652018-03-28
CVE-2018-20100 7.49.80.00712019-01-02
CVE-2017-9632 7.39.80.00472017-08-07
CVE-2019-3431 7.39.80.00402019-12-23
CVE-2023-0750 7.39.80.00452023-04-06
CVE-2023-4420 7.29.80.00242023-08-24
CVE-2023-6339 7.210.00.00182024-01-02
CVE-2020-12032 7.09.10.00942020-06-29
CVE-2019-18800 6.98.80.01662019-11-06
CVE-2021-27779 6.99.10.00582022-05-25