{"data":{"id":"SC-16","name":"Transmission of Security and Privacy Attributes","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Associate [Assignment: organization-defined security and privacy attributes] with information exchanged between systems and between system components.","supplemental_guidance":"Security and privacy attributes can be explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes are abstractions that represent the basic properties or characteristics of an entity with respect to protecting information or the management of personally identifiable information. Attributes are typically associated with internal data structures, including records, buffers, and files within the system. Security and privacy attributes are used to implement access control and information flow control policies; reflect special dissemination, management, or distribution instructions, including permitted uses of personally identifiable information; or support other aspects of the information security and privacy policies. Privacy attributes may be used independently or in conjunction with security attributes.","enhancements":[{"id":"SC-16(01)","name":"Integrity Verification","statement":"Verify the integrity of transmitted security and privacy attributes.","baselines":[]},{"id":"SC-16(02)","name":"Anti-spoofing Mechanisms","statement":"Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.","baselines":[]},{"id":"SC-16(03)","name":"Cryptographic Binding","statement":"Implement [Assignment: organization-defined mechanisms or techniques] to bind security and privacy attributes to transmitted information.","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-16","name":"Transmission of Security and Privacy Attributes","description":"Associate [Assignment: organization-defined security and privacy attributes] with information exchanged between systems and between system components.","discussion":"Security and privacy attributes can be explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes are abstractions that represent the basic properties or characteristics of an entity with respect to protecting information or the management of personally identifiable information. Attributes are typically associated with internal data structures, including records, buffers, and files within the system. Security and privacy attributes are used to implement access control and information flow control policies; reflect special dissemination, management, or distribution instructions, including permitted uses of personally identifiable information; or support other aspects of the information security and privacy policies. Privacy attributes may be used independently or in conjunction with security attributes.","related_controls":["AC-03","AC-04","AC-16"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Transmission of Security Attributes' Parameter adds 'and privacy'   Discussion expanded to provide detailed explanation of attributes"}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["PR.DS-02"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.24","RGS.2.2","SecNumCloud.14.2"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.C(63)"],"gdpr":["Art.32(1)(a)"],"dora":["Art.9(3)"],"bio2":[],"rbi_csf":[],"fisc":["FISC.T12"],"lgpd_bcb":[],"hkma_tme1":["TME1.9.3"],"mlps_2":[],"dnb_good_practice":["DNB.2.2","DNB.18.5"],"cra":["CRA.I.2f"],"swift_cscf":[],"qatar_nia":["CS"],"sa_js2":["JS2-6.1"],"bcbs_239":["Principle 3","Principle 7"],"cpmi_pfmi":["PFMI.P22"],"ffiec_is":["II.C.5"],"iosco_cyber":["PROT-3"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FDP"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["07.b"],"iso_27799":[],"lloyds_ms":["BP2.2","MS6.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Reliable association of security parameters with exchanged information ensures that server software components processing data maintain proper security labeling, detecting unauthorized modifications to data handling by malicious server components."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Transmitting security parameters alongside encrypted communications enables receiving systems to validate the expected security classification and handling requirements of data within adversary-mimicked encrypted channels."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Security parameter association with email transport data ensures that transport agents processing messages maintain proper security labeling, detecting malicious transport agents that strip or modify security markings."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Associating security parameters with symmetric encrypted communications enables detection of improperly labeled C2 traffic by verifying that security classifications match expected parameters for encrypted data exchanges."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Transmitting security parameters with asymmetric encrypted data enables receiving systems to validate expected security markings, detecting adversary encrypted channels that lack proper security parameter associations."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-02 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to ---, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}