← Controls / SC

SC-08 Transmission Confidentiality and Integrity

System and Communications Protection

Moderate High

Description

Protect the [Selection (one or more): confidentiality; integrity] of transmitted information.

Supplemental Guidance

Protecting the confidentiality and integrity of transmitted information applies to internal and external networks as well as any system components that can transmit information, including servers, notebook computers, desktop computers, mobile devices, printers, copiers, scanners, facsimile machines, and radios. Unprotected communication paths are exposed to the possibility of interception and modification. Protecting the confidentiality and integrity of information can be accomplished by physical or logical means. Physical protection can be achieved by using protected distribution systems. A protected distribution system is a wireline or fiber-optics telecommunications system that includes terminals and adequate electromagnetic, acoustical, electrical, and physical controls to permit its use for the unencrypted transmission of classified information. Logical protection can be achieved by employing encryption techniques. Organizations that rely on commercial providers who offer transmission services as commodity services rather than as fully dedicated services may find it difficult to obtain the necessary assurances regarding the implementation of needed controls for transmission confidentiality and integrity. In such situations, organizations determine what types of confidentiality or integrity services are available in standard, commercial telecommunications service packages. If it is not feasible to obtain the necessary controls and assurances of control effectiveness through appropriate contracting vehicles, organizations can implement appropriate compensating controls.

Enhancements (5)

What NIST adds to this control. Select one to read its statement.

SC-08(01) Cryptographic Protection ModerateHigh

Implement cryptographic mechanisms to [Selection (one or more): prevent unauthorized disclosure of information; detect changes to information] during transmission.

SC-08(02) Pre- and Post-transmission Handling

Maintain the [Selection (one or more): confidentiality; integrity] of information during preparation for transmission and during reception.

SC-08(03) Cryptographic Protection for Message Externals

Implement cryptographic mechanisms to protect message externals unless otherwise protected by [Assignment: organization-defined alternative physical controls].

SC-08(04) Conceal or Randomize Communications

Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by [Assignment: organization-defined alternative physical controls].

SC-08(05) Protected Distribution System

Implement [Assignment: organization-defined protected distribution system] to [Selection (one or more): prevent unauthorized disclosure of information; detect changes to information] during transmission.

Compliance Mappings

ISO 27001:2022

A.5.10A.5.14A.5.33A.8.20A.8.21A.8.26

ISO 27002:2022

5.148.208.21

CIS Controls v8

CIS 3CIS 3.10CIS 12.3CIS 12.6

NIST CSF 2.0

PR.DS-02

SOC 2 TSC

CC6.1CC6.7

PCI DSS v4.0.1

2.2.74.14.2

CSA CCM v4

CEK-03DSP-10DSP-17IPY-03IVS-03

CSA AICM v1

CEK-03DSP-10DSP-17I&S-03IPY-03

FINOS CCC

CCC-C01

IEC 62443

3-3 SR 3.13-3 SR 4.1

NIS2 Directive

Art. 21(2)(h)Art. 21(2)(j)

PRA Operational Resilience

SS2/21-11.1

MAS TRM

1014

APRA CPS 234

Para 22-23

BSI IT-Grundschutz

APP.3.1CON.1

ANSSI

Hygiene.24RGS.2.3SecNumCloud.11.1SecNumCloud.14.2

FINMA Circular 2023/1

IV.C(63)IV.D(78)IV.D(81)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(a)Rec.83

EU DORA

Art.9(3)Art.9(4)(a)

BIO2

5.148.208.21

RBI CSF

Annex1.4Annex1.10ITGRCA.16

FISC Security Guidelines

FISC.T4FISC.T8FISC.T10FISC.T11FISC.T12

LGPD + BCB 4893

BCB.Art.3BCB.Art.14BCB.OpenFinanceBCB.PIXLGPD.Art.33-36LGPD.Art.46

HKMA TM-E-1

TME1.8.5TME1.9.1TME1.10.1TME1.10.2TME1.10.3TME1.11.2

MLPS 2.0

8.1.2.28.1.4.78.1.4.88.4

DNB Good Practice

DNB.12.3DNB.18.4DNB.18.5

EU CRA

CRA.I.2eCRA.I.2fCRA.II.7

SWIFT CSCF

SWIFT.2.1SWIFT.2.4ASWIFT.2.5ASWIFT.2.6

SAMA CSF

3.33.43.84.3

NCA ECC

2-42-52-8

UAE IA

T8

CBB TM

TM-8TM-9

Qatar NIA

CS

CBUAE

CR-5CR-8

CBE CSF

CTO-2CTO-3CTO-5CTO-6CTO-8

SA JS2

JS2-7.2JS2-8.2JS2-8.3

CBN CSF

Part3.3Part3.4Part5.2

BoG CISD

CISD-IXCISD-VICISD-VIIICISD-XICISD-XIICISD-XIII

POPIA

s19

BoM CTRM

3.23.43.103.13

IOSCO Cyber Resilience

PROT-3RR-3

BCBS 239

Principle 3Principle 11

CPMI-IOSCO PFMI

CG.PRPFMI.P17PFMI.P22

FFIEC IS

II.C.6II.C.9II.C.13II.C.13(b)II.C.15(c)II.C.16II.C.19

NYDFS 500

500.15

HIPAA Security Rule

§164.312(c)(1)§164.312(c)(2)§164.312(e)(1)§164.312(e)(2)(i)§164.312(e)(2)(ii)

ECB CROE

CROE.2.3.3CROE.2.3.5

EBA ICT Guidelines

3.8(b)

SEBI CSCRF

EMAIL-SECPR.CSPR.DSPR.NS

BOT Cyber Resilience

Ch2.3Ch2.4Ch2.7Ch9.1

CMMC 2.0

SC

NERC CIP

CIP-012-1

10 CFR 73.54

RG5.71-A-SC

IEEE 1686-2022

5.5

FERC CIP Orders

Order 2222

API 1164

Sec 8

IAEA NSS 17-T

Sec 5.6

PCI PTS v6

EIJ

CBEST

CBEST.9

TIBER-EU

TIBER.CONF

PCI HSM

3

Common Criteria

CC Part 2 — FCSCC Part 2 — FDPCC Part 2 — FPT

ISAE 3402

Clause 4

Solvency II

Art.49(3)DR.266-DataSecEIOPA-Cloud-GL9EIOPA-ICT-4.6EIOPA-ICT-4.7

Lloyd's Minimum Standards

BP2.1BP2.2MS6.1MS8.9MS13.2

NAIC Insurance Data Security

4-encryption4B

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.b09.e09.f10.c

FDA 21 CFR Part 11

§11.30§11.70§11.300(d)

FDA Cybersecurity Guidance

SA-2SA-4

ISO 27799

10.113.113.2H.2H.5

NHS DSPT

NDG-1.1NDG-9.2NDG-9.4NDG-9.6

OWASP MASVS v2.1

MASVS-NETWORK-1MASVS-NETWORK-2

CCSS v9.0

1.01.41.06.4

MiCA

Art.76(1)Art.97(1)

Basel SCO60

SCO60.71

BSSC Standards

GSP-13NOS-04TIS-05

India DPDPA

Act.8(5)Rules.6(1)(a)Rules.Sch1.B.2Rules.Sch1.B.7Rules.Sch2

ISO 17799 (legacy)

10.6.110.8.110.9.1

COBIT 4.1 (legacy)

AC6