Encryption at rest

Encryption at rest protects data sitting on a disk. If somebody walks off with the drive, or the laptop, or the backup tape, what they have is unreadable.

That is the whole of what it does, and the limit catches people out. It does not protect data from anything using the system normally, because for that use the data is being decrypted on the fly, as designed. An attacker who has got into a running application is not stopped by it at all. It is genuinely valuable, and it answers the question of theft rather than the question of intrusion.

Checked against the primary source.

More on Cryptography