# Security

Intel DC persistent memory modules support data-at-rest security by encrypting the data stored in the persistent regions of the DIMM. The CLI only supports transitioning to Disable Security State using the Change Device Security command.

{% hint style="info" %}
**NOTE:** Security commands are subject to OS Vendor (OSV) support and will return "Not Supported." An exception is if the module is in Unlocked Security State, then transitioning to Disabled is permitted.
{% endhint %}

For further security information, refer to the [Managing NVDIMM Security](https://docs.pmem.io/ndctl-user-guide/managing-nvdimm-security) section of the NDCTL user guide.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.pmem.io/ipmctl-user-guide/v1.x/security.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
