# SC-08 Transmission Confidentiality and Integrity

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Protect the [Selection (one or more): confidentiality; integrity] of transmitted information.
Guidance: Protecting the confidentiality and integrity of transmitted information applies to internal and external networks as well as any system components that can transmit information, including servers, notebook computers, desktop computers, mobile devices, printers, copiers, scanners, facsimile machines, and radios. Unprotected communication paths are exposed to the possibility of interception and modification. Protecting the confidentiality and integrity of information can be accomplished by physical or logical means. Physical protection can be achieved by using protected distribution systems. A protected distribution system is a wireline or fiber-optics telecommunications system that includes terminals and adequate electromagnetic, acoustical, electrical, and physical controls to permit its use for the unencrypted transmission of classified information. Logical protection can be achieved by employing encryption techniques. Organizations that rely on commercial providers who offer transmission services as commodity services rather than as fully dedicated services may find it difficult to obtain the necessary assurances regarding the implementation of needed controls for transmission confidentiality and integrity. In such situations, organizations determine what types of confidentiality or integrity services are available in standard, commercial telecommunications service packages. If it is not feasible to obtain the necessary controls and assurances of control effectiveness through appropriate contracting vehicles, organizations can implement appropriate compensating controls.

## Enhancements (5)
- SC-08(01) Cryptographic Protection. Baselines: moderate, high
- SC-08(02) Pre- and Post-transmission Handling
- SC-08(03) Cryptographic Protection for Message Externals
- SC-08(04) Conceal or Randomize Communications
- SC-08(05) Protected Distribution System
Each enhancement's statement: /api/v1/controls/SC-08?fields=enhancements

## Patterns that use it (24)
- Critical (10): SP-005 SOA Internal Service Usage Pattern; SP-006 Wireless- Private Network Pattern; SP-007 Wireless- Public Hotspot Pattern; SP-015 Secure Remote Working; SP-029 Zero Trust Architecture; SP-030 API Security; SP-032 Modern Authentication; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-050 Mobile Security Architecture (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (12): SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-013 Data Security Pattern; SP-017 Secure Network Zone Module; SP-022 Board of Directors Room; SP-033 Passkey Authentication; SP-039 Client-Side Encryption and Data Privacy; SP-042 Third Party Risk Management; SP-047 Secure Agentic AI Frameworks; SP-051 Tokenised Asset Security Architecture (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft); SP-053 Zero-Knowledge Proof Architecture (draft)
- Standard (2): SP-023 Industrial Control Systems; SP-028 Secure DevOps Pipeline Pattern

## Clauses by framework (79 frameworks)
- iso_27001_2022: A.5.10, A.5.14, A.5.33, A.8.20, A.8.21, A.8.26. OSA's own, not in NIST's crosswalk: A.8.21
- iso_27002_2022: 5.14, 8.20, 8.21
- pci_dss_v4: 2.2.7, 4.1, 4.2
- nist_csf_2: PR.DS-02
- cis_controls_v8: CIS 3, CIS 3.10, CIS 12.3, CIS 12.6
- soc2_tsc: CC6.1, CC6.7
- finos_ccc: CCC-C01
- iec_62443: 3-3 SR 3.1, 3-3 SR 4.1
- nis2: Art. 21(2)(h), Art. 21(2)(j)
- apra_cps_234: Para 22-23
- mas_trm: 10, 14
- pra_op_resilience: SS2/21-11.1
- bsi_grundschutz: APP.3.1, CON.1
- anssi: Hygiene.24, RGS.2.3, SecNumCloud.11.1, SecNumCloud.14.2
- osfi_b13: B-13.3.2
- finma_circular: IV.C(63), IV.D(78), IV.D(81)
- gdpr: Art.5(1)(f), Art.32(1)(a), Rec.83
- dora: Art.9(3), Art.9(4)(a)
- bio2: 5.14, 8.20, 8.21
- rbi_csf: Annex1.4, Annex1.10, ITGRCA.16
- fisc: FISC.T4, FISC.T8, FISC.T10, FISC.T11, FISC.T12
- lgpd_bcb: BCB.Art.3, BCB.Art.14, BCB.OpenFinance, BCB.PIX, LGPD.Art.33-36, LGPD.Art.46
- hkma_tme1: TME1.8.5, TME1.9.1, TME1.10.1, TME1.10.2, TME1.10.3, TME1.11.2
- mlps_2: 8.1.2.2, 8.1.4.7, 8.1.4.8, 8.4
- dnb_good_practice: DNB.12.3, DNB.18.4, DNB.18.5
- cra: CRA.I.2e, CRA.I.2f, CRA.II.7
- swift_cscf: SWIFT.2.1, SWIFT.2.4A, SWIFT.2.5A, SWIFT.2.6
- cbb_tm: TM-8, TM-9
- cbuae: CR-5, CR-8
- nca_ecc: 2-4, 2-5, 2-8
- qatar_nia: CS
- sama_csf: 3.3, 3.4, 3.8, 4.3
- uae_ia: T8
- bog_cisd: CISD-IX, CISD-VI, CISD-VIII, CISD-XI, CISD-XII, CISD-XIII
- bom_ctrm: 3.2, 3.4, 3.10, 3.13
- cbe_csf: CTO-2, CTO-3, CTO-5, CTO-6, CTO-8
- cbn_csf: Part3.3, Part3.4, Part5.2
- popia: s19
- sa_js2: JS2-7.2, JS2-8.2, JS2-8.3
- bcbs_239: Principle 3, Principle 11
- bot_cyber: Ch2.3, Ch2.4, Ch2.7, Ch9.1
- cpmi_pfmi: CG.PR, PFMI.P17, PFMI.P22
- eba_ict: 3.8(b)
- ecb_croe: CROE.2.3.3, CROE.2.3.5
- ffiec_is: II.C.6, II.C.9, II.C.13, II.C.13(b), II.C.15(c), II.C.16, II.C.19
- hipaa_sr: §164.312(c)(1), §164.312(c)(2), §164.312(e)(1), §164.312(e)(2)(i), §164.312(e)(2)(ii)
- iosco_cyber: PROT-3, RR-3
- nydfs_500: 500.15
- sebi_cscrf: EMAIL-SEC, PR.CS, PR.DS, PR.NS
- cmmc_2: SC
- nerc_cip: CIP-012-1
- nrc_73_54: RG5.71-A-SC
- ieee_1686: 5.5
- ferc_cip: Order 2222
- api_1164: Sec 8
- iaea_nss: Sec 5.6
- pci_pts: E, I, J
- cbest: CBEST.9
- tiber_eu: TIBER.CONF
- pci_hsm: 3
- common_criteria: CC Part 2 — FCS, CC Part 2 — FDP, CC Part 2 — FPT
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.30, §11.70, §11.300(d)
- fda_cyber: SA-2, SA-4
- hitrust_csf: 01.b, 09.e, 09.f, 10.c
- iso_27799: 10.1, 13.1, 13.2, H.2, H.5
- lloyds_ms: BP2.1, BP2.2, MS6.1, MS8.9, MS13.2
- naic_ds: 4-encryption, 4B
- nhs_dspt: NDG-1.1, NDG-9.2, NDG-9.4, NDG-9.6
- solvency_ii: Art.49(3), DR.266-DataSec, EIOPA-Cloud-GL9, EIOPA-ICT-4.6, EIOPA-ICT-4.7
- owasp_masvs_v2: MASVS-NETWORK-1, MASVS-NETWORK-2
- csa_ccm_v4: CEK-03, DSP-10, DSP-17, IPY-03, IVS-03
- csa_aicm: CEK-03, DSP-10, DSP-17, I&S-03, IPY-03
- ccss_v9: 1.01.4, 1.06.4
- mica: Art.76(1), Art.97(1)
- basel_sco60: SCO60.71
- bssc: GSP-13, NOS-04, TIS-05
- dpdpa: Act.8(5), Rules.6(1)(a), Rules.Sch1.B.2, Rules.Sch1.B.7, Rules.Sch2
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-08
- Clauses only: /api/v1/controls/SC-08?fields=mappings
- Page for people: /controls/sc-08/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
