Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section III. Encryption of data at rest
  4. Data at rest encryption security
  5. About NetBackup client encryption
  6. About running an encryption backup
  7. About choosing encryption for a backup
NetBackup™ Security and Encryption Guide

About choosing encryption for a backup

When a backup is started, the server determines from a policy attribute whether the backup should be encrypted. The server then connects to bpcd on the client to initiate the backup and passes the Encryption policy attribute on the backup request.

The client compares the Encryption policy attribute to the CRYPT_OPTION in the configuration on the client as follows:

  • If the policy attribute is yes and CRYPT_OPTION is REQUIRED or ALLOWED, the client performs an encrypted backup.

  • If the policy attribute is yes and CRYPT_OPTION is DENIED, the client performs no backup.

  • If the policy attribute is no and CRYPT_OPTION is ALLOWED or DENIED, the client performs a non-encrypted backup.

  • If the policy attribute is no and CRYPT_OPTION is REQUIRED, the client does not perform the backup.

The following table shows the type of backup that is performed for each condition:

Table: Type of backup performed

CRYPT_OPTION

Encryption policy attribute with CRYPT_OPTION

Encryption policy attribute without CRYPT_OPTION

REQUIRED

Encrypted

None

ALLOWED

Encrypted

Non-encrypted

DENIED

None

Non-encrypted

See Standard encryption backup process.

See NetBackup standard encryption restore process.

See Legacy encryption backup process.

See NetBackup legacy encryption restore process.

Feedback

Was this page helpful?
Previous

About running an encryption backup

Next

Standard encryption backup process

Feedback

Was this page helpful?